(3)
(5)
(6)
25.
(1)
(2)
(3)
(4)
26.
(1)
(2)
(3)
Sub-Article (1) of this Article does not apply to records of personal data retained for
historical, statistical, or research purposes.
A person who retains records for historical, statistical or research purposes shall ensure
that the records that contain the personal data are adequately protected against access
or use for unauthorized purposes.
A person who uses a record of the personal data of a data subject to make a decision
about the data subject shall retain the record for a period required or prescribed by law
or a code of conduct.
The Principle of Integrity and Confidentiality
The data controller shall take reasonable steps to ensure the reliability of any employees
of his who have access to the personal data.
Where processing of personal data is carried out by a data processor on behalf of a data
controller, the data controller shall in order to comply with this principle:
(a) choose a data processor who provides sufficient guarantees in respect of the
technical and organizational security measures governing the processing to be
carried out; and
(b) take reasonable steps to ensure compliance with those measures.
Where processing of personal data is carried out by a data processor on behalf of a data
controller, the data controller is not to be regarded as complying with this principle
unless:
(a) the processing is carried out under a contract which is made or evidenced in
writing;
(b) the data processor is to act only on instructions from the data controller; and
(c) the contract requires the data processor to comply with obligations equivalent to
those imposed on a data controller by the principle of integrity and confidentiality.
The data controller and data processor shall take technical steps to ensure that any
individual acting under their authority and has access to personal data does not process
the personal data except on instructions from the data controller, unless he is required
to do so by a law.
The Principle of Security
Appropriate technical and organizational measures shall be taken against unauthorized
or unlawful processing of personal data and against accidental loss or destruction of, or
damage to personal data.
For the purposes of the application of the principle of integrity and confidentiality
regard shall be made to the state of technological development.
The measures referred in sub-Article (2) of this Article must ensure a level of security
appropriate to
(a) the harm that might result from such unauthorized or unlawful processing or
accidental loss, destruction or damage; and
(b) the nature of the data to be protected.
13