10
Chapter 7 — Data security and storage of personal data
Section 32 — Data security
(1) The controller shall carry out the technical and organisational measures necessary for securing
personal data against unauthorised access, against accidental or unlawful destruction,
manipulation, disclosure and transfer and against other unlawful processing. The techniques
available, the associated costs, the quality, quantity and age of the data, as well as the
significance of the processing to the protection of privacy shall be taken into account when
carrying out the measures.
(2) Anyone who as an independent trader or business operates on the behalf of the controller shall,
before starting the processing of data, provide the controller with appropriate commitments and
other adequate guarantees of the security of the data as provided in paragraph (1).
Section 33 — Secrecy obligation
Anyone who has gained knowledge of the characteristics, personal circumstances or economic
situation of another person while carrying out measures relating to data processing shall not
disclose the data to a third person against the provisions of this Act.
Section 34 — Destruction of a personal data file
If a personal data file is no longer necessary for the operations of the controller, it shall be
destroyed, unless specific provisions have been issued by an Act or by lower-level regulation
on the continued storage of the data contained therein or the file is transferred to be archived in
accordance with section 35.
Section 35 — Transfer of personal data to be archived
(1) Separate provisions apply to the use and protection of personal data files which have been
transferred to the possession of the archive authorities, as well as to the disclosure of data
from such files. However, when disclosing personal data from a private file, the archive
authority shall take into account the provisions in this Act on the processing and disclosure of
personal data, unless this, in view of the age or nature of the data recorded in the file, is
manifestly unnecessary for the protection of the privacy of the data subjects.
(2) A personal data file which is significant for purposes of scientific research or otherwise may
be transferred for archiving to an institution of higher education or to a research institute or
authority operating on a statutory basis, where the National Archives have granted a
permission for such archiving. The National Archives may grant corporations, foundations and
institutions a permission to archive personal data files compiled in their own activities and
fulfilling the requirements above. In the permission the National Archives shall lay down rules
for the protection of the files and for the monitoring of the use of the personal data.
(3) Before granting a permission referred to in paragraph (2). the National Archives shall reserve
the Data Protection Ombudsman an opportunity to issue an opinion on the matter.
Chapter 8 — Notification to the Data Protection Ombudsman
Section 36 — Duty of notification
(1) The controller shall notify the Data Protection Ombudsman of automated data processing by
sending a description of the file to that authority.
(2) In addition, the controller shall notify the Data Protection Ombudsman of:
(1) the transfer of personal data to outside the European Union or the European Economic
Area, if the data are transferred on the grounds provided in section 22 or 23(6) or (7)
and there is no statutory provision on the same; or
(2) the launching of an automated decision-making system referred to in section 31.
(3) Anyone who is engaged in credit data activity or carrying out debt collection or market or
opinion research as a business, or operating in recruitment, personnel assessment or computing
on the behalf of another, and who uses or processes files or personal data in this activity, shall