Cyber Security and Data Protection or unauthorised destruction, negligent loss, unauthorised alteration or access and any other unauthorised processing of the data. 5 (2) These measures referred to in subsection (1) must ensure an appropriate level of security taking into account the state of technological development and the cost of implementing the measures on the one hand, and the nature of the data to be protected and the potential risks to the data subject on the other hand. (3) The Authority may issue appropriate standards relating to information security for all or certain categories of processing. 10 15 (4) The data controller shall appoint data processor who provide sufficient guarantees regarding the technical and organisational security measures employed to protect the data associated with the processing undertaken and ensure strict adherence to such measures. (5) The data controller shall enter into a written contract or any other legal instrument with the data processor which ensures that the data processor maintains security measures on data. 19 Security breach notification The data controller shall notify the Authority, without any undue delay of any security breach affecting data he or she processes. 20 20 Obligation of notification to Authority (1) Prior to any wholly or partly automated operation or set of operations intended to serve a single purpose or several related purposes, the controller or his or her representative, if any, must notify the Authority. (2) Any modification to the information provided according to section 16 must be notified to the Authority. 25 30 35 (3) The provisions of subsection (1) shall not apply to operations having the sole purpose of keeping a register that is intended to provide information to the public by virtue of operation of law and that is open to access by the general public or by any person demonstrating a legitimate interest. (4) The Authority may exempt certain categories from notification under this section if— (a) taking into account the data being processed, there is no apparent risk of infringement of the data subjects’ rights and freedoms, and if the purposes of the processing, the categories of data being processed, the categories of data subjects, the categories of recipients and the data retention period are specified; (b) the data controller has appointed a data protection officer. (5) The appointment of the data protection officer shall be duly notified to the Authority. 40 (6) The Authority shall provide guidelines that provide for the qualifications and functions of data protection officer. (7) If exemption from the duty of notification has been granted for automatic processing in accordance with the subsection 3, the data controller may disclose the items of information mentioned in section 16 to any person entitled to receive such information. 13

Seleccionar párrafo de destino3