juris

Section 31: Security of processing

Data Protection Act 2017 · PART IV: OBLIGATIONS ON CONTROLLERS AND PROCESSORS

as enacted (not consolidated). juris shows this Act from a copy that is not the official consolidation, so it may not carry every amendment; the amendments juris holds are listed. It does not confirm that this is the law in force today.

31. Security of processing (1) A controller or processor shall, at the time of the determination of the means for processing and at the time of the processing – (a) implement appropriate security and organisational measures for – (i) the prevention of unauthorised access to; 494 Acts 2017 Acts 2017 495 (ii) the alteration of; (iii) the disclosure of; (iv) the accidental loss of; and (v) the destruction of, the data in his control; and (b) ensure that the measures provide a level of security appropriate for – (i) the harm that might result from – (A) the unauthorised access to; (B) the alteration of; (C) the disclosure of; (D) the destruction of, the data and its accidental loss; and (ii) the nature of the data concerned. (2) (a) The measures referred to in subsection (1) shall include – (i) the pseudonymisation and encryption of personal data; (ii) the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services; (iii) the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident; and (iv) a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of the processing. (b) The Office may lay down technical standards for the requirements specified in paragraph (a). 496 Acts 2017 Acts 2017 497 (3) In determining the appropriate security measures referred to in subsection (1), in particular, where the processing involves the transmission of data over an information and communication network, a controller shall have regard to – (a) the state of technological development available; (b) the cost of implementing any of the security measures; (c) the special risks that exist in the processing of the data; and (d) the nature of the data being processed. (4) Where a controller is using the services of a processor – (a) he or it shall choose a processor providing sufficient guarantees in respect of security and organisational measures for the purpose of complying with subsection (1); and (b) the controller and the processor shall enter into a written contract which shall provide that – (i) the processor shall act only on instructions received from the controller; and (ii) the processor shall be bound by obligations devolving on the controller under subsection (1). (5) Where a processor processes personal data other than as instructed by the controller, the processor shall be considered to be a controller in respect of that processing. (6) Every controller or processor shall take all reasonable steps to ensure that any person employed by him or it is aware of, and complies with, the relevant security measures.

Ask juris about this section Official source