(3) (5) (6) 25. (1) (2) (3) (4) 26. (1) (2) (3) Sub-Article (1) of this Article does not apply to records of personal data retained for historical, statistical, or research purposes. A person who retains records for historical, statistical or research purposes shall ensure that the records that contain the personal data are adequately protected against access or use for unauthorized purposes. A person who uses a record of the personal data of a data subject to make a decision about the data subject shall retain the record for a period required or prescribed by law or a code of conduct. The Principle of Integrity and Confidentiality The data controller shall take reasonable steps to ensure the reliability of any employees of his who have access to the personal data. Where processing of personal data is carried out by a data processor on behalf of a data controller, the data controller shall in order to comply with this principle: (a) choose a data processor who provides sufficient guarantees in respect of the technical and organizational security measures governing the processing to be carried out; and (b) take reasonable steps to ensure compliance with those measures. Where processing of personal data is carried out by a data processor on behalf of a data controller, the data controller is not to be regarded as complying with this principle unless: (a) the processing is carried out under a contract which is made or evidenced in writing; (b) the data processor is to act only on instructions from the data controller; and (c) the contract requires the data processor to comply with obligations equivalent to those imposed on a data controller by the principle of integrity and confidentiality. The data controller and data processor shall take technical steps to ensure that any individual acting under their authority and has access to personal data does not process the personal data except on instructions from the data controller, unless he is required to do so by a law. The Principle of Security Appropriate technical and organizational measures shall be taken against unauthorized or unlawful processing of personal data and against accidental loss or destruction of, or damage to personal data. For the purposes of the application of the principle of integrity and confidentiality regard shall be made to the state of technological development. The measures referred in sub-Article (2) of this Article must ensure a level of security appropriate to (a) the harm that might result from such unauthorized or unlawful processing or accidental loss, destruction or damage; and (b) the nature of the data to be protected. 13

Select target paragraph3