Data Protection
No. 24 of 2019
[Subsidiary]
(2) In reviewing the data protection impact assessment report, the Data Commissioner
may make any recommendations to be incorporated prior to commencing the processing
operations.
(3) Where a data controller or data processor, upon submitting the data protection impact
assessment report to the Data Commissioner, does not receive any communication within
sixty days of submission, may commence processing operations and the assessment report
shall be taken to have been approved.
(4) A data controller or data processor may publish on its website the data protection
impact assessment Report.
53. Audit of compliance with Assessment Report
Pursuant to section 23 of the Act, the Data Commissioner may carry out periodic audits
to monitor compliance with the Assessment Report and any recommendations that may
have been provided by the Data Commissioner.
PART IX – PROVISIONS ON EXEMPTIONS UNDER THE ACT
54. Exemption for national security
(1) For the purposes of section 51(2) (b) of the Act, the processing of personal data by
a national security organ referred to in Article 239 (1) of the Constitution in furtherance of
their mandate constitutes a processing for national security.
(2) Despite sub-regulation (1), a data controller or data processor who processes
personal data for national security and wishes to be exempt on that ground shall apply to
the Cabinet Secretary for an exemption.
(3) The Cabinet Secretary shall, upon being satisfied that the grounds supporting the
application are sufficient, issue a certificate of exemption.
(4) The Cabinet Secretary may revoke a certificate of exemption issued, at any time,
where the grounds on which the certificate was issued no longer apply.
55. Exemptions for public interest
For the purposes of section 51(2) (b) of the Act, the processing of personal data is
exempted from the Act on the grounds of public interest where such processing exists as a—
(a)
permitted general situation; or
(b)
permitted health situation.
56. Permitted general situation
A permitted general situation referred to under regulation 55 (a) relates to the collection,
use or disclosure by a data controller or data processor of personal data about data subject
including for—
(a)
lessening or preventing a serious threat to the life, health or safety of any data
subject, or to public health or safety;
(b)
taking appropriate action in relation to suspected unlawful activity or serious
misconduct;
(c)
locating a person reported as missing;
(d)
asserting a legal or equitable claim;
(e)
conducting an alternative dispute resolution process; or
(f)
performing diplomatic or consular duties.
57. Permitted health situation
(1) A permitted health situation referred to under regulation 55 (b) relates to the
collection, use or disclosure by a data controller or data processor of personal data about
a data subject, including for—
(a)
the collection of health information to provide a health service;
37