(4)
(5)
(6)
Taking into account the state of the art, the nature, scope, context and purposes of
processing as well as the risk of varying likelihood and severity for the rights and
freedoms of individuals, the data controller and the data processor shall implement
appropriate technical and organizational measures to ensure a level of security
appropriate to the risk, including:
(a) the pseudonymization and encryption of personal data;
(b) the ability to ensure the ongoing confidentiality, integrity, availability and
resilience of processing systems and services;
(c) the ability to restore the availability and access to personal data in a timely manner
in the event of a physical or technical incident; and
(d) a process for regularly testing, assessing and evaluating the effectiveness of
technical and organizational measures for ensuring the security of the processing.
In assessing the appropriate level of security account shall be taken in particular of the
risks that are presented by processing.
For the purpose of sub-Article (5) of this Article, risks shall include in particular those
risks from accidental or unlawful destruction, loss, alteration, unauthorized disclosure
of, or access to personal data transmitted, stored or otherwise processed.
27.
The Principle of Data Transfer
Without prejudice to the provisions on data transfer, the transfer to a third party jurisdiction
of personal data that is to undergo processing may only take place subject to the provisions
of this Proclamation and provided that the third party jurisdiction to which the data is to be
transferred ensures appropriate levels of protection.
28.
(1)
(2)
(3)
Level of Protection in Third Party Jurisdiction
The appropriate level of protection stipulated under Article 27 of this Proclamation shall
be assessed in the light of all the circumstances surrounding a data transfer operation or
a set of data transfer operations before the data is transferred.
For the purpose of sub-Article (1) of this Article, particular consideration shall be given
to the nature of the data, the purpose and duration of the proposed processing operation
or operations, the country of origin and country of final destination, the rules of law in
force in the third party jurisdiction and the professional rules and security measures
which are complied within that jurisdiction.
Where, despite the absence of appropriate levels of protection, the Commission
determines that some limited form of transfer may be facilitated which would limit the
breach of the data subject’s rights in accordance with this Proclamation, the Commission
may authorize such a transfer where:
(a) the data subject consents to the transfer of the data to the third party jurisdiction;
and
(b) there is appropriate severance or reduction of those aspects of the data which the
Commission deems appropriate.
14