6. The Requirement of Data Protection Section 7 (1) The controller must plan and execute control operations in a way that these ensure the protection of the private sphere throughout the application of the present Act and other regulations applicable in connection with data control. (2) The controller, as well as the data processor within their respective scope of activities, is obliged to ensure data security, institute technical and organisational measures and develop procedural rules required to enforce the present Act, as well as other data protection and confidentiality rules. (3) Through the institution of the appropriate measures the data must be particularly protected from unauthorised access, modification, transfer, disclosure, deletion or destruction, accidental destruction and damage as well as disabled access occurring due to changes to the technology applied. (4) In order to protect data sets controlled electronically in various files it is necessary to ensure that – unless otherwise permitted by law - data stored in files cannot be directly connected and linked to the data subject by ensuring the appropriate technological solutions. (5) During the course of the automated processing of personal data, the controller and data processor ensures the following by taking additional measures: a. prevents unauthorised data entry; b. prevents the use of automatic data processing systems by unauthorised persons by using data transfer devices; c. ensures the ability to control and determine which bodies the personal data have or can be sent to by using a data transfer device; d. ensures the ability to control and determine which personal data has been registered in the automatic data processing systems, when this was done and who did it; e. ensures the ability to restore the systems installed in the event of malfunctions and; f. compiles a report on errors occurring during the course of automated processing. a. The controller and data processor must take account of the current level of development of the relevant technology when determining and applying measures taken to protect the data. The solution which ensures a higher level protection of the personal data must be selected from among several possible control solutions, unless this proves far too difficult for the controller. 7. Data Transfer to Other Countries Section 8 (1) Data processors under the scope of the present Act are authorised to transfer personal data to controllers or data processors undertaking data control in third countries should a. the data subject have provided their explicit consent, or b. conditions set out under Section 5 and Section 6 have been fulfilled and the adequate level protection of the personal data have been ensured in the third country during the course of the control and processing of the data transferred. (2) Adequate level control of the personal data is ensured should a. this be stated in a binding legal act of the European Union, or b. an international treaty specifically containing the enforcement of rights specified under Section 14 and the assurance of legal redress for the data subject, as well as rules guaranteeing the independent control of the control and data processing procedure concluded between the third country and Hungary be in effect. (3) Personal data may be transferred to third countries to execute an international agreement to

Select target paragraph3