English
1/Appropriate technical and organizational
measures shall be taken against unauthorized or
unlawful processing of personal data and
against accidental loss or destruction of, or
damage to personal data.
2/ For the purposes of the application of the
principle of integrity and confidentiality regard
shall be made to the state of technological
development.
3/ The measures referred in Sub-Article
(2) of this
Article must ensure a level of security
appropriate to :
a) The harm that might result from such
unauthorized or unlawful processing or
accidental loss, destruction or damage; and
b) It must ensure security levels commensurate
with nature of the the data to be protected.
4/ Taking into account the state of the art, the
nature, scope, context and purposes of
processing as well as the risk of varying
likelihood and severity for the rights and
freedoms of individuals, the data controller and
the data processor shall implement appropriate
technical and organizational measures to ensure
a level of security appropriate to the risk,
including:
a) the pseudonymization and encryption of
personal data;
b) the ability to ensure the ongoing
confidentiality, integrity, availability and
resilience of processing systems and services;
c) the ability to restore the availability and access
to personal data in a timely manner in the
event of a physical or technical incident; and
d) A process for regularly testing, assessing and
evaluating the effectiveness of technical and
organizational measures for ensuring the
security of the processing.
5/ In assessing the appropriate level of security
account shall be taken in particular of the risks
that are presented by processing.
6/ For the purpose of Sub-Article
(5) of this Article,
risks shall include in particular those risks from
accidental or unlawful destruction, loss,
alteration, unauthorized disclosure of, or access
to personal data transmitted, stored or otherwise
processed.