(4)
(5)
52.
(1)
(2)
A person may be designated or appointed as a data protection officer, if that person has
relevant academic or professional qualifications which may include knowledge and
technical skills in matters relating to data protection.
A data controller or data processor shall publish the contact details of the data protection
officer and communicate them to the Commission.
Duties of Data Protection Officer
The responsibility of a data protection officer shall be to:
(a) advise the data controller or data processor and their employees on data
processing requirements provided under this Proclamation or any other law;
(b) ensure on behalf of the data controller or data processor that this Proclamation is
complied with;
(c) facilitate capacity building of staff involved in data processing operations;
(d) provide advice on data protection impact assessment; and
(e) cooperate with the Commission and any other authority on matters relating to
data protection.
Notwithstanding the provisions of sub-Article (1) of this Article, a data protection officer
may be a staff member of the data controller or data processor and may fulfill other tasks
and duties provided that any such tasks and duties do not result in a conflict of interest.
Section Two
Obligations on Data Controllers and Data Processors
53. Technical and Organizational Measures
(1) The data controller and data processor shall implement the appropriate technical and
organizational measures to ensure that processing is performed in accordance with this
Proclamation.
(2) The measures referred to in sub-Article (1) of this Article shall include:
(a) implementing appropriate data security and organizational measures;
(b) keeping a record of all processing operations;
(c) performing a data protection impact assessment;
(d) complying with the requirements for prior authorization from, or consultation
with the Commission; and
(e) designating a data protection officer.
(3) Every data controller and data processor shall implement such internal policies and
mechanisms as may be required to ensure verification of the effectiveness of the
measures referred to in this Article.
54.
(1)
Notification of Personal Data Breach
Where there is a personal data breach, the data controller shall within 72 hours after
having become aware of it, notify the personal data breach to the Commission.
23