d)
are adequate, relevant and not excessive in relation to the purpose of the
processing, and
e)
are accurate and up-to-date, and are not stored longer than is necessary for the
purpose of the processing, cf. sections 27 and 28.
Subsequent processing of personal data for historical, statistical or scientific
purposes is not deemed to be incompatible with the original purposes of the collection
of the data, cf. first paragraph, litra c, if the public interest in the processing being
carried out clearly exceeds the disadvantages this may entail for natural persons.
Section 12 Use of national identity numbers, etc.
National identity numbers and other clear means of identification may only be
used in the processing when there is a objective need for certain identification and the
method is necessary to achieve such identification.
The Data Inspectorate may require a controller to use such means of
identification as are mentioned in the first paragraph to ensure that the personal data are
of adequate quality.
The King may by regulations prescribe further rules regarding the use of
national identity numbers and other clear means of identification.
Section 13 Data security
The controller and the processor shall by means of planned, systematic measures
ensure satisfactory data security with regard to confidentiality, integrity and
accessibility in connection with the processing of personal data.
To achieve satisfactory data security, the controller and processor shall
document the data system and the security measures. Such documentation shall be
accessible to the employees of the controller and of the processor. The documentation
shall also be accessible to the Data Inspectorate and the Privacy Appeals Board.
Any controller who allows other persons to have access to personal data, e.g. a
processor or other persons performing tasks in connection with the data system, shall
ensure that the said persons fulfil the requirements set out in the first and second
paragraphs.
The King may prescribe regulations regarding data security in connection with
the processing of personal data, including further rules regarding organisational and
technical security measures.
Section 14 Internal control
The controller shall establish and maintain such planned and systematic
measures as are necessary to fulfil the requirements laid down in or pursuant to this Act,
including measures to ensure the quality of personal data.
The controller shall document the measures. The documentation shall be
accessible to the employees of the controller and of the processor. The documentation
shall also be accessible to the Data Inspectorate and the Privacy Appeals Board.
The King may prescribe regulations containing further rules regarding internal
control.
Section 15 The processor’s right of disposition over personal data
No processor may process personal data in any way other than that which is
agreed in writing with the controller. Nor may the data be turned over to another person
for storage or manipulation without such agreement.