6
Data Protection Act, 2018 - 5.
(b) to any party other than a third party of the class of third parties as
in section 8(d).
specified
10. Security Principle.
(1) A data user shall, when processing personal data, take practical steps to protect
the personal data from any loss, misuse, modification, unauthorised or accidental access or
disclosure, alteration or destruction by having regard–
(a) to the nature of the personal data and the harm that would result from such
loss, misuse, modification, unauthorised or accidental access or disclosure,
alteration or destruction;
(b) to the place or location where the personal data is stored;
(c) to any security measures incorporated into any equipment in which the personal
data is stored;
(d) to the measures taken for ensuring the reliability, integrity and competence of
personnel having access to the personal data; and
(e) to the measures taken for ensuring the secure transfer of the personal data.
(2) Where processing of personal data is carried out by a data processor on behalf of
the data user, the data user shall, for the purpose of protecting the personal data from any
loss, misuse, modification, unauthorised or accidental access or disclosure, alteration or
destruction, ensure that the data processor–
(a) provides sufficient guarantees in respect of the technical and organisational
security measures governing the processing to be carried out; and
(b) takes reasonable steps to ensure compliance with those measures.
11. Retention Principle.
(1) The personal data processed for any purpose shall not be kept longer than is
necessary for the fulfillment of that purpose.
(2) It shall be the duty of a data user to take all reasonable steps to ensure that all
personal data is destroyed or permanently deleted if it is no longer required for the purpose
for which it was to be processed.
12. Data Integrity Principle.
A data user shall take reasonable steps to ensure that the personal data is accurate,
complete, not misleading and kept up-to-date by having regard to the purpose, including any
directly related purpose, for which the personal data was collected and further processed.
13. Access Principle.
A data subject shall be given access to his or her personal data held by a data user
and be able to correct that personal data where the personal data is inaccurate, incomplete,
misleading or not up-to-date, except where compliance with a request to such access or
correction is refused under this Act.