Cyber Security and Data Protection
or unauthorised destruction, negligent loss, unauthorised alteration or access and any
other unauthorised processing of the data.
5
(2) These measures referred to in subsection (1) must ensure an appropriate
level of security taking into account the state of technological development and the
cost of implementing the measures on the one hand, and the nature of the data to be
protected and the potential risks to the data subject on the other hand.
(3) The Authority may issue appropriate standards relating to information
security for all or certain categories of processing.
10
15
(4) The data controller shall appoint data processor who provide sufficient
guarantees regarding the technical and organisational security measures employed to
protect the data associated with the processing undertaken and ensure strict adherence
to such measures.
(5) The data controller shall enter into a written contract or any other legal
instrument with the data processor which ensures that the data processor maintains
security measures on data.
19
Security breach notification
The data controller shall notify the Authority, without any undue delay of any
security breach affecting data he or she processes.
20
20
Obligation of notification to Authority
(1) Prior to any wholly or partly automated operation or set of operations
intended to serve a single purpose or several related purposes, the controller or his or
her representative, if any, must notify the Authority.
(2) Any modification to the information provided according to section 16 must
be notified to the Authority.
25
30
35
(3) The provisions of subsection (1) shall not apply to operations having the
sole purpose of keeping a register that is intended to provide information to the public
by virtue of operation of law and that is open to access by the general public or by any
person demonstrating a legitimate interest.
(4) The Authority may exempt certain categories from notification under this
section if—
(a) taking into account the data being processed, there is no apparent risk of
infringement of the data subjects’ rights and freedoms, and if the purposes
of the processing, the categories of data being processed, the categories
of data subjects, the categories of recipients and the data retention period
are specified;
(b) the data controller has appointed a data protection officer.
(5) The appointment of the data protection officer shall be duly notified to the
Authority.
40
(6) The Authority shall provide guidelines that provide for the qualifications
and functions of data protection officer.
(7) If exemption from the duty of notification has been granted for automatic
processing in accordance with the subsection 3, the data controller may disclose the
items of information mentioned in section 16 to any person entitled to receive such
information.
13