No. 24 of 2019 Data Protection [Subsidiary] (e) the ability to justify why the period of storage is necessary for the purpose, and disclosing the rationale behind the retention period; and (f) determining which personal data and length of storage is necessary for backups and logs. 36. Elements for principle of fairness The elements necessary to implement the principle of fairness include— (a) granting the data subjects the highest degree of autonomy with respect to control over their personal data; (b) enabling a data subject to communicate and exercise their rights; (c) elimination of any discrimination against a data subject; (d) guarding against the exploitation of the needs or vulnerabilities of a data subject; and (e) incorporating human intervention to minimize biases that automated decisionmaking processes may create. PART VI – NOTIFICATION OF PERSONAL DATA BREACHES 37. Categories of notifiable data breach (1) For the purpose of section 43 of the Act, a data breach is taken to result in real risk of harm to a data subject if that data breach relates to — (a) the data subject’s full name or identification number and any of the personal data or classes of personal data relating to the data subject set out in the Second Schedule; or (b) the following personal data relating to a data subject’s account with a data controller or data processor— (i) the data subject’s account identifier, such as an account name or number; and (ii) any password, security code, access code, response to a security question, biometric data or other data that is used or required to allow access to or use of the individual’s account. (2) A breach of any personal data envisaged under sub-regulation (1) amounts to notifiable data breach under section 43 of the Act. (3) The personal data or classes of personal data set out in the Second Schedule excludes — (a) any personal data that is publicly available; or (b) any personal data that is disclosed to the extent that is required or permitted under any written law. (4) The personal data referred to in sub-paragraph (3) (a) shall not be publicly available solely because of any data breach. 38. Notification to Data Commissioner (1) A notification by data controller to the Data Commissioner of a notifiable data breach under section 43 of the Act shall include— (a) the date on which and the circumstances in which the data controller or data processor first became aware that the data breach had occurred; (b) a chronological account of the steps taken by the data controller or data processor after the data controller or data processor became aware that the data breach had occurred, including the data controller or data processor’s assessment that the data breach is a notifiable data breach; (c) details on how the notifiable data breach occurred, where applicable; 32

Select target paragraph3