Personal Data Protection Act
GN. NO. 395B (Contd)
security standards as provided by this Act.
(5) The data controller shall notify the
Commission, without any undue delay, of any security
breach affecting personal data being processed by or on
behalf of the data controller.
Retention and
disposal of
personal data
28.-(1) Where a data controller uses personal
data for a specified purpose as specified under section
25, he shall retain that personal data for a period
specified in the relevant laws or a period prescribed in
the regulations in order to ensure that the data subject
has a reasonable opportunity to access the personal data
where need arises.
(2) Subject to subsection (1), the Minister may,
by regulations prescribe the retention and disposal of
personal data held by a data controller in accordance
with the purpose of retention.
Correction of
personal data
29.-(1) Where a document or file to which
access has been given under this Act contains personal
data and that data subject claims that the personal data(a) is incomplete, incorrect or misleading; or
(b) not relevant to the purpose for which the
document is held,
the data controller may, subject to procedures as may be
prescribed in the regulations and upon receiving and
being satisfied with the application of the data subject,
amend the personal data.
(2) The data controller shall, when making an
amendment to personal data in a document under this
section, ensure that he does not permanently delete the
record of the text of the document as it existed prior to
the amendment.
(3) Where a data controller is not satisfied with
the reasons for an application under subsection (1), he
may refuse to make any amendment to the personal data
and inform the applicant of the reasons for refusal.
18