(4) (5) (6) Taking into account the state of the art, the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of individuals, the data controller and the data processor shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including: (a) the pseudonymization and encryption of personal data; (b) the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services; (c) the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident; and (d) a process for regularly testing, assessing and evaluating the effectiveness of technical and organizational measures for ensuring the security of the processing. In assessing the appropriate level of security account shall be taken in particular of the risks that are presented by processing. For the purpose of sub-Article (5) of this Article, risks shall include in particular those risks from accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data transmitted, stored or otherwise processed. 27. The Principle of Data Transfer Without prejudice to the provisions on data transfer, the transfer to a third party jurisdiction of personal data that is to undergo processing may only take place subject to the provisions of this Proclamation and provided that the third party jurisdiction to which the data is to be transferred ensures appropriate levels of protection. 28. (1) (2) (3) Level of Protection in Third Party Jurisdiction The appropriate level of protection stipulated under Article 27 of this Proclamation shall be assessed in the light of all the circumstances surrounding a data transfer operation or a set of data transfer operations before the data is transferred. For the purpose of sub-Article (1) of this Article, particular consideration shall be given to the nature of the data, the purpose and duration of the proposed processing operation or operations, the country of origin and country of final destination, the rules of law in force in the third party jurisdiction and the professional rules and security measures which are complied within that jurisdiction. Where, despite the absence of appropriate levels of protection, the Commission determines that some limited form of transfer may be facilitated which would limit the breach of the data subject’s rights in accordance with this Proclamation, the Commission may authorize such a transfer where: (a) the data subject consents to the transfer of the data to the third party jurisdiction; and (b) there is appropriate severance or reduction of those aspects of the data which the Commission deems appropriate. 14

Select target paragraph3