(4) (5) 52. (1) (2) A person may be designated or appointed as a data protection officer, if that person has relevant academic or professional qualifications which may include knowledge and technical skills in matters relating to data protection. A data controller or data processor shall publish the contact details of the data protection officer and communicate them to the Commission. Duties of Data Protection Officer The responsibility of a data protection officer shall be to: (a) advise the data controller or data processor and their employees on data processing requirements provided under this Proclamation or any other law; (b) ensure on behalf of the data controller or data processor that this Proclamation is complied with; (c) facilitate capacity building of staff involved in data processing operations; (d) provide advice on data protection impact assessment; and (e) cooperate with the Commission and any other authority on matters relating to data protection. Notwithstanding the provisions of sub-Article (1) of this Article, a data protection officer may be a staff member of the data controller or data processor and may fulfill other tasks and duties provided that any such tasks and duties do not result in a conflict of interest. Section Two Obligations on Data Controllers and Data Processors 53. Technical and Organizational Measures (1) The data controller and data processor shall implement the appropriate technical and organizational measures to ensure that processing is performed in accordance with this Proclamation. (2) The measures referred to in sub-Article (1) of this Article shall include: (a) implementing appropriate data security and organizational measures; (b) keeping a record of all processing operations; (c) performing a data protection impact assessment; (d) complying with the requirements for prior authorization from, or consultation with the Commission; and (e) designating a data protection officer. (3) Every data controller and data processor shall implement such internal policies and mechanisms as may be required to ensure verification of the effectiveness of the measures referred to in this Article. 54. (1) Notification of Personal Data Breach Where there is a personal data breach, the data controller shall within 72 hours after having become aware of it, notify the personal data breach to the Commission. 23

Sélectionner le paragraphe cible3