20
security of
personal data
Data Protection
No. 3
(c) advise the data controller or data processor on data
protection impact assessments; and
(d) act as the contact point for the authority and the data
controller or data processor, on compliance matters under this
act.
Part VI—Data securIty
35.__(1) a data controller and data processor shall, taking into
account—
(a) the cost of technology;
(b) the nature, scope, context and purpose of processing
personal data;
(c) the degree and likelihood of harm to a data subject that
could result from the loss, disclosure or other misuse of personal
data; and
(d) the retention period of personal data,
implement appropriate technical and organizational measures
to ensure the security of personal data under the control or
possession of the data controller or data processor.
(2) notwithstanding the generality of subsection (1), a data
controller and data processor shall implement the following
measures to ensure the security of personal data—
(a) pseudonymization or any other method of de-identification
of personal data;
(b) encryption of personal data;
(c) develop and implement procedures to restore availability
and access to personal data in a timely manner in the event of a
physical or technical incident;
(d) conduct periodic risk assessment of the data processing
system and service including, without limitation, where the
processing involves the transmission of personal data over an
electronic communication network;
(e) conduct regular testing, assessment and evaluation of the
effectiveness of the measures implemented under this section and
section 30 against current and evolving risks; and
(f) carry out regular updates of the measures implemented
under this section and introduce new measures to address any
shortcomings in effectiveness identified and address evolving
risks.