No. 24 of 2019
Data Protection
[Subsidiary]
(e)
the ability to justify why the period of storage is necessary for the purpose,
and disclosing the rationale behind the retention period; and
(f)
determining which personal data and length of storage is necessary for backups and logs.
36. Elements for principle of fairness
The elements necessary to implement the principle of fairness include—
(a)
granting the data subjects the highest degree of autonomy with respect to
control over their personal data;
(b)
enabling a data subject to communicate and exercise their rights;
(c)
elimination of any discrimination against a data subject;
(d)
guarding against the exploitation of the needs or vulnerabilities of a data
subject; and
(e)
incorporating human intervention to minimize biases that automated decisionmaking processes may create.
PART VI – NOTIFICATION OF PERSONAL DATA BREACHES
37. Categories of notifiable data breach
(1) For the purpose of section 43 of the Act, a data breach is taken to result in real risk
of harm to a data subject if that data breach
relates to —
(a)
the data subject’s full name or identification number and any of the personal
data or classes of personal data relating to the data subject set out in the
Second Schedule; or
(b)
the following personal data relating to a data subject’s account with a data
controller or data processor—
(i)
the data subject’s account identifier, such as an account name or
number; and
(ii)
any password, security code, access code, response to a security
question, biometric data or other data that is used or required to allow
access to or use of the individual’s account.
(2) A breach of any personal data envisaged under sub-regulation (1) amounts to
notifiable data breach under section 43 of the Act.
(3) The personal data or classes of personal data set out in the Second Schedule
excludes —
(a)
any personal data that is publicly available; or
(b)
any personal data that is disclosed to the extent that is required or permitted
under any written law.
(4) The personal data referred to in sub-paragraph (3) (a) shall not be publicly available
solely because of any data breach.
38. Notification to Data Commissioner
(1) A notification by data controller to the Data Commissioner of a notifiable data breach
under section 43 of the Act shall include—
(a)
the date on which and the circumstances in which the data controller or data
processor first became aware that the data breach had occurred;
(b)
a chronological account of the steps taken by the data controller or data
processor after the data controller or data processor became aware that the
data breach had occurred, including the data controller or data processor’s
assessment that the data breach is a notifiable data breach;
(c)
details on how the notifiable data breach occurred, where applicable;
32