(a) (b) (c) (d) If these data are necessary to prevent or discover a crime on official request from the investigation authorities. If these data are required or authorized by any law or by a court decision. If these data are necessary for the estimation or collection of any taxes or fees. If the processing is necessary for the protection of the person from whom data is collected. Article (44) Subject to the second paragraph of the above article, the authentication service provider shall follow the appropriate procedure to ensure confidentiality of the personal data in his possession in the course of his business and he shall not be allowed to disclose or transfer or declare or publicize these data for any purpose. Article (45) Any person who controls any personal data by virtue of his job in electronic transactions shall, before processing such data, notify the person from whom it is collected by a designated notice of the procedure he is following to protect those data. These procedures shall include an identification of the person responsible for processing the data, the nature of the data, and the purpose, methods and locations of processing and all informations necessary to ensure secured data processing. Article (46) The authentication service provider shall, upon the request of the person from whom data is collected, enable that person to have access to or update those personal data. Such right shall include the right of accessing all personal databases related to the person from whom it is collected, and shall make available to him all the appropriate technical means for this purpose. Article (47) The users of the personal data collected pursuant to Article (43) of this law, shall not be allowed to send electronic documents to the person from whom such data is collected if he explicitly refuses to accept them. Article (48) Any person controlling personal data is not allowed to process these data if the processing will cause damage to persons from whom such data is collected or will prejudice their rights and freedoms. Article (49) When the personal data are supposed to be transferred outside Oman, regard shall be had to the security of such information, in particular: (a) Nature of personal data. (b) Source of information and data. (c) Purpose for which the data are to be processed and duration of process. (d) The country of destination where the data were transferred, its international obligation, and the law applicable. (e) Any related rules applied in that country. (f) The security measures taken to secure that data in that country. 15

Seleccionar párrafo de destino3