(2) The provisions of previous paragraph (1) shall not apply is not
applicable where:
(a) informing the data subject proves impossible or would
involve a disproportionate effort, in particular for data
collected for statistical purposes or for the purpose of
historical or scientific research, or for the purpose of medical
examination of the population with a view to protecting and
promoting public health;
or
(b) personal data is recorded or provided with a view to the
application of a provision laid down by or by virtue of an act,
decree or ordinance.
(3) The Authority shall establish the conditions for the application
of this Paragraph.
Authority to
process
23.
Any person having access to the personal data and acting under
the authority of the controller or of the processor, as well as the
processor himself/herself, may process personal data only as
instructed by the controller, without prejudice to any duty imposed
by law.
Security
24.
(1)
(a) In order to safeguard the security, integrity and confidentiality
of the personal data, the controller or his/her representative,
if any, as well as the processor, shall must take the
appropriate technical and organizational measures that are
necessary to protect the personal data from negligent or
unauthorized destruction, negligent loss, as well as from
unauthorised alteration or access and any other
unauthorized processing of the personal data.
(b) These measures must ensure an appropriate level of
security taking into account the state of technological
development and the cost of implementing the measures on
the one hand, and the nature of the data to be protected
and the potential risks to the data subject on the other
hand.
(c) The Authority may issue appropriate standards relating to
information security for all or certain categories of
processing.
Draft Data Protection Bill Version 1.0
34