Section 22: Duties of controller
as enacted (not consolidated). juris shows this Act from a copy that is not the official consolidation, so it may not carry every amendment; the amendments juris holds are listed. It does not confirm that this is the law in force today.
22. Duties of controller
(1) Every controller shall adopt policies and implement
appropriate technical and organisational measures so as to ensure and be
able to demonstrate that the processing of personal data is performed in
accordance with this Act.
(2) The measures referred to in subsection (1) shall include –
(a) implementing appropriate data security and
organisational measures in accordance with section 31;
(b) keeping a record of all processing operations in
accordance with section 33;
(c) performing a data protection impact assessment in
accordance with section 34;
(d) complying with the requirements for prior authorisation
from, or consultation with the Commissioner pursuant
to section 35; and
(e) designating an officer responsible for data protection
compliance issues.
(3) Every controller shall implement such policies and
mechanisms as may be required to ensure verification of the effectiveness
of the measures referred to in this section.