16
Derogations
adherence to
data protection
principles
technical and
organizational
measures
record of
personal data
processing
activities
Data Protection
No. 3
(b) authorized by a written law which has suitable measures to
safeguard the rights and interests of the data subject; or
(c) based on the consent of the data subject.
(3) where an exception under subsection (2) applies, a data
controller shall implement the appropriate measures to safeguard
the rights and interests of the data subject.
26.__the rights of a data subject provided under this Part may be
restricted where the processing of the personal data of the data
subject is for the purpose of—
(a) national security, including safeguarding against and the
prevention of a threat to national security;
(b) the prevention, investigation, detection or prosecution of a
criminal offence or the execution of a criminal penalty;
(c) pursuing a national economic or financial interest,
including a monetary, budgetary and taxation matter;
(d) public health;
(e) social security;
(f) judicial proceedings;
(g) the prevention, investigation, detection and prosecution of
a breach of ethics for a regulated profession;
(h) monitoring, inspection or exercise of a regulatory function
by a public authority;
(i) protecting the data subject or the rights and freedoms of
another natural person; or
(j) the enforcement of a civil law claim.
Part V—DutIes OF a Data cOntrOLLer anD Data PrOcessOr
27.
a data controller and data processor shall adhere to the
principles relating to processing of personal data prescribed under
Part III.
28.
a data controller and data processor shall develop and
implement appropriate technical and organizational measures to
ensure that the processing of personal data complies with the
provisions of this act.
29.__(1) a data controller and data processor shall maintain, in
writing, a record of each personal data processing activity.
(2) the record referred to in subsection (1) shall contain—