Act
Data Protection And Privacy Act
2019
(d) ensure that the safeguards are continually updated in
response to new risks or deficiencies.
(3) A data controller shall observe generally accepted
information security practices and procedures , and specific industry
or professional rules and regulations .
21. Security measures relating to data processed by data
processor.
(1) A data controller shall not permit a data processor to process
personal data for the data controller, unless the data processor
establishes and complies with the security measures specified under
this Act.
(2) A contract between a data controller and a data processor
relating to processing of personal data, shall require the data
processor to establish and maintain the confidentiality and security
measures necessary to protect the integrity of the personal data.
22. Data processed by operator or authorised person.
(1) An operator or a person who processes personal data on
behalf of a data controller shall process the data only with the prior
knowledge or authorisation of the data controller and shall treat the
personal data which comes to the knowledge of the operator or other
person as confidential.
(2) A data processor shall not disclose the data unless required
by law, or in the course of the discharge of a duty.
23. Notification of data security breaches.
(1) Where a data collector, data processor or data controller,
believes that the personal data of a data subject has been accessed or
acquired by an unauthorised person , the data collector, data processor
or data controller , shall immediately notify the Authority in the
prescribed manner, of the unauthorised access or acquisition and the
remedial action taken.