No. 24 of 2019 Data Protection [Subsidiary] (d) a data subject knowing what they consented to and a simplified means to withdraw consent; and (e) restriction of processing where the legal basis or legitimate interests ceases to apply. 30. Elements for principle of transparency The elements necessary to implement the principle of transparency include— (a) the use of clear, simple and plain language to communicate with a data subject to enable a data subject to make decisions on the processing of their personal data; (b) making the information on the processing easily accessible to the data subject; (c) providing the information on the processing to the data subject at the relevant time and in the appropriate form; (d) the use of machine-readable language to facilitate and automate readability and clarity; (e) providing a fair understanding of the expectation with regards to the processing particularly for children or other vulnerable groups; and (f) providing details of the use and disclosure of the personal data of a data subject. 31. Elements for principle of purpose limitation The elements necessary to implement the principle of purpose limitation include— (a) specifying the purpose for each processing of personal data; (b) determining the legitimate purposes for the processing of personal data before designing organisational measures and safeguards; (c) the purpose for the processing being the determinant for personal data collected; (d) ensuring a new purpose is compatible with the original purpose for which the data was collected; (e) regularly reviewing whether the processing is necessary for the purposes for which the data was collected and test the design against purpose limitation; and (f) the use of technical measures, including hashing and cryptography, to limit the possibility of repurposing personal data. 32. Elements for principle of integrity, confidentiality and availability The elements necessary to implement the principle of integrity, confidentiality and availability include— (a) having an operative means of managing policies and procedures for information security; (b) assessing the risks against the security of personal data and putting in place measures to counter identified risks; (c) processing that is robust to withstand changes, regulatory demands, incidents, and cyber-attacks; (d) ensuring only authorised personnel have access to the data necessary for their processing tasks; (e) securing transfers shall be secured against unauthorised access and changes; (f) securing data storage from use, unauthorised access and alterations; (g) keeping back-ups and logs to the extent necessary for information security; 30

Select target paragraph3