(3) (4) (5) 60. (1) (2) (3) (4) (5) 61. (1) (2) (3) (4) 62. Where the Commission is of the opinion that the intended processing does not comply with this Proclamation, it shall prohibit the intended processing and make appropriate proposals to remedy such non-compliance. The Commission shall make public a list of the processing operations which are subject to prior consultation in accordance with sub-Article (2) lit. (b) of this Article. The data controller or data processor shall provide the Commission with the data protection impact assessment and, whenever requested, any other information. Data Protection by Design and by Default The data controller, where applicable, the data processor shall both at the time of the determination of the means for processing and at the time of the processing itself, implement appropriate technical and organizational measures designed to: (a) implement the personal data processing principles set out in this Proclamation in an effective manner; and (b) integrate the necessary safeguards into the processing in order to meet the requirements of this Proclamation and protect the rights of data subjects. The measures stipulated under sub-Article (1) of this Article shall take into consideration the state of the art, the nature, scope, context and purposes of processing as well as the risks of varying likelihood and severity for rights and freedoms of individuals posed by the processing. The data controller shall implement the appropriate technical and organizational measures for ensuring that, by default, only personal data which are necessary for each specific purpose of the processing is processed. Sub-Article (3) of this Article applies to the amount of personal data collected, the extent of processing of the personal data, the period of storage of the personal data and the accessibility to the personal data. The technical and organizational measures referred to in sub-Article (1) of this Article shall ensure that personal data is not, by default, made accessible without the individual's intervention to an indefinite number of individuals. Duty to Destroy Personal Data Unless the contrary is stipulated under Article 24 of this Proclamation, where the purpose for storing personal data has lapsed, every data controller shall destroy or delete the personal data as soon as is reasonably practicable. The destruction or deletion of a record of personal data shall be done in a manner that prevents its reconstruction in an intelligible form. The data controller shall have the duty to notify any data processor holding the data of its obligation under this Article. Any data processor who receives a notification under sub-Article (3) of this Article shall, as soon as is reasonably practicable, destroy the data specified by the data controller. Joint Data Controllers 27

Select target paragraph3