No. 24 of 2019
Data Protection
[Subsidiary]
(d)
a data subject knowing what they consented to and a simplified means to
withdraw consent; and
(e)
restriction of processing where the legal basis or legitimate interests ceases
to apply.
30. Elements for principle of transparency
The elements necessary to implement the principle of transparency include—
(a)
the use of clear, simple and plain language to communicate with a data
subject to enable a data subject to make decisions on the processing of their
personal data;
(b)
making the information on the processing easily accessible to the data
subject;
(c)
providing the information on the processing to the data subject at the relevant
time and in the appropriate form;
(d)
the use of machine-readable language to facilitate and automate readability
and clarity;
(e)
providing a fair understanding of the expectation with regards to the
processing particularly for children or other vulnerable groups; and
(f)
providing details of the use and disclosure of the personal data of a data
subject.
31. Elements for principle of purpose limitation
The elements necessary to implement the principle of purpose limitation include—
(a)
specifying the purpose for each processing of personal data;
(b)
determining the legitimate purposes for the processing of personal data
before designing organisational measures and safeguards;
(c)
the purpose for the processing being the determinant for personal data
collected;
(d)
ensuring a new purpose is compatible with the original purpose for which the
data was collected;
(e)
regularly reviewing whether the processing is necessary for the purposes for
which the data was collected and test the design against purpose limitation;
and
(f)
the use of technical measures, including hashing and cryptography, to limit
the possibility of repurposing personal data.
32. Elements for principle of integrity, confidentiality and availability
The elements necessary to implement the principle of integrity, confidentiality and
availability include—
(a)
having an operative means of managing policies and procedures for
information security;
(b)
assessing the risks against the security of personal data and putting in place
measures to counter identified risks;
(c)
processing that is robust to withstand changes, regulatory demands,
incidents, and cyber-attacks;
(d)
ensuring only authorised personnel have access to the data necessary for
their processing tasks;
(e)
securing transfers shall be secured against unauthorised access and
changes;
(f)
securing data storage from use, unauthorised access and alterations;
(g)
keeping back-ups and logs to the extent necessary for information security;
30