Data Protection
No. 24 of 2019
[Subsidiary]
(h)
using audit trails and event monitoring as a routine security control;
(i)
protecting sensitive personal data with adequate measures and, where
possible, kept separate from the rest of the personal data;
(j)
having in place routines and procedures to detect, handle, report, and learn
from data breaches; and
(k)
regularly reviewing and testing software to uncover vulnerabilities of the
systems supporting the processing.
33. Elements for principle of data minimization
The elements necessary to implement the principle of data minimization include—
(a)
avoiding the processing of personal data altogether when this is possible for
the relevant purpose;
(b)
limiting the amount of personal data collected to what is necessary for the
purpose;
(c)
ability to demonstrate the relevance of the data to the processing in question;
(d)
pseudonymising personal data as soon as the data is no longer necessary
to have directly identifiable personal data, and storing identification keys
separately;
(e)
anonymizing or deleting personal data where the data is no longer necessary
for the purpose;
(f)
making data flows efficient to avoid the creation of more copies or entry points
for data collection than is necessary; and
(g)
the application of available and suitable technologies for data avoidance and
minimization.
34. Elements for principle of accuracy
The elements necessary to implement the principle of accuracy include—
(a)
ensuring data sources are reliable in terms of data accuracy;
(b)
having personal data particulars being accurate as necessary for the specified
purposes;
(c)
verification of the correctness of personal data with the data subject before
and at different stages of the processing depending on the nature of the
personal data, in relation to how often it may change;
(d)
erasing or rectifying inaccurate data without delay;
(e)
mitigating the effect of an accumulated error in the processing chain;
(f)
giving data subjects an overview and easy access to personal data in order
to control accuracy and rectify as needed;
(g)
having personal data accurate at all stages of the processing and carrying
out tests for accuracy at critical steps;
(h)
updating personal data as necessary for the purpose; and
(i)
the use of technological and organisational design features to decrease
inaccuracy.
35. Elements for principle of storage limitation
The elements necessary to implement the principle of storage limitation include—
(a)
having clear internal procedures for deletion and destruction;
(b)
determining what data and length of storage of personal data that is necessary
for the purpose;
(c)
formulating internal retention statements of implementing them;
(d)
ensuring that it is not possible to re-identify anonymised data or recover
deleted data and testing whether this is possible;
31