juris

Section 22: Duties of controller

Data Protection Act 2017 · PART IV: OBLIGATIONS ON CONTROLLERS AND PROCESSORS

as enacted (not consolidated). juris shows this Act from a copy that is not the official consolidation, so it may not carry every amendment; the amendments juris holds are listed. It does not confirm that this is the law in force today.

22. Duties of controller (1) Every controller shall adopt policies and implement appropriate technical and organisational measures so as to ensure and be able to demonstrate that the processing of personal data is performed in accordance with this Act. (2) The measures referred to in subsection (1) shall include – (a) implementing appropriate data security and organisational measures in accordance with section 31; (b) keeping a record of all processing operations in accordance with section 33; (c) performing a data protection impact assessment in accordance with section 34; (d) complying with the requirements for prior authorisation from, or consultation with the Commissioner pursuant to section 35; and (e) designating an officer responsible for data protection compliance issues. (3) Every controller shall implement such policies and mechanisms as may be required to ensure verification of the effectiveness of the measures referred to in this section.

Ask juris about this section Official source