6 Data Protection Act, 2018 - 5. (b) to any party other than a third party of the class of third parties as in section 8(d). specified 10. Security Principle. (1) A data user shall, when processing personal data, take practical steps to protect the personal data from any loss, misuse, modification, unauthorised or accidental access or disclosure, alteration or destruction by having regard– (a) to the nature of the personal data and the harm that would result from such loss, misuse, modification, unauthorised or accidental access or disclosure, alteration or destruction; (b) to the place or location where the personal data is stored; (c) to any security measures incorporated into any equipment in which the personal data is stored; (d) to the measures taken for ensuring the reliability, integrity and competence of personnel having access to the personal data; and (e) to the measures taken for ensuring the secure transfer of the personal data. (2) Where processing of personal data is carried out by a data processor on behalf of the data user, the data user shall, for the purpose of protecting the personal data from any loss, misuse, modification, unauthorised or accidental access or disclosure, alteration or destruction, ensure that the data processor– (a) provides sufficient guarantees in respect of the technical and organisational security measures governing the processing to be carried out; and (b) takes reasonable steps to ensure compliance with those measures. 11. Retention Principle. (1) The personal data processed for any purpose shall not be kept longer than is necessary for the fulfillment of that purpose. (2) It shall be the duty of a data user to take all reasonable steps to ensure that all personal data is destroyed or permanently deleted if it is no longer required for the purpose for which it was to be processed. 12. Data Integrity Principle. A data user shall take reasonable steps to ensure that the personal data is accurate, complete, not misleading and kept up-to-date by having regard to the purpose, including any directly related purpose, for which the personal data was collected and further processed. 13. Access Principle. A data subject shall be given access to his or her personal data held by a data user and be able to correct that personal data where the personal data is inaccurate, incomplete, misleading or not up-to-date, except where compliance with a request to such access or correction is refused under this Act.

Select target paragraph3