Data Protection No. 24 of 2019 [Subsidiary] (h) using audit trails and event monitoring as a routine security control; (i) protecting sensitive personal data with adequate measures and, where possible, kept separate from the rest of the personal data; (j) having in place routines and procedures to detect, handle, report, and learn from data breaches; and (k) regularly reviewing and testing software to uncover vulnerabilities of the systems supporting the processing. 33. Elements for principle of data minimization The elements necessary to implement the principle of data minimization include— (a) avoiding the processing of personal data altogether when this is possible for the relevant purpose; (b) limiting the amount of personal data collected to what is necessary for the purpose; (c) ability to demonstrate the relevance of the data to the processing in question; (d) pseudonymising personal data as soon as the data is no longer necessary to have directly identifiable personal data, and storing identification keys separately; (e) anonymizing or deleting personal data where the data is no longer necessary for the purpose; (f) making data flows efficient to avoid the creation of more copies or entry points for data collection than is necessary; and (g) the application of available and suitable technologies for data avoidance and minimization. 34. Elements for principle of accuracy The elements necessary to implement the principle of accuracy include— (a) ensuring data sources are reliable in terms of data accuracy; (b) having personal data particulars being accurate as necessary for the specified purposes; (c) verification of the correctness of personal data with the data subject before and at different stages of the processing depending on the nature of the personal data, in relation to how often it may change; (d) erasing or rectifying inaccurate data without delay; (e) mitigating the effect of an accumulated error in the processing chain; (f) giving data subjects an overview and easy access to personal data in order to control accuracy and rectify as needed; (g) having personal data accurate at all stages of the processing and carrying out tests for accuracy at critical steps; (h) updating personal data as necessary for the purpose; and (i) the use of technological and organisational design features to decrease inaccuracy. 35. Elements for principle of storage limitation The elements necessary to implement the principle of storage limitation include— (a) having clear internal procedures for deletion and destruction; (b) determining what data and length of storage of personal data that is necessary for the purpose; (c) formulating internal retention statements of implementing them; (d) ensuring that it is not possible to re-identify anonymised data or recover deleted data and testing whether this is possible; 31

Select target paragraph3