CHAPTER VII
SECURITY OF PERSONAL DATA
Article 27
Measures for the security of personal data
1. The controller or the processor shall take appropriate organizational and technical measures in order to protect personal data from unlawful or accidental destruction,
accidental loss, from access or disclosure to unauthorized
persons, especially when the processing of data takes place
in a network, as well as from any other unlawful form of
processing.
2. The controller shall take the following special security measures:
a) defines the functions of the organizational units and
those of the operators as regards the use of data;
b) data shall be used with the order of authorized
organizational units or operators;
c) instructs all operators concerning their obligations,
in conformity with this law and the internal regulations on
data protection, including the regulations on data security;
ç) Prohibits access of unauthorized persons to the
working facilities of the data controller or processors;
d) data and programmes shall be accessed only by authorized persons;
dh) Prohibits access to the filing system and their use
by unauthorized persons;
30
e) Operation of the data processing equipment shall
be carried out upon authorization and every device shall
be secured with preventive measures against unauthorized
operation;
ë) records and documents the alteration, rectification,
erasure, transfer, etc.
2.1. The controller is obliged to document the technical
and organizational measures adjusted and implemented to
ensure protection of personal data in compliance with the
law and other legal regulations.
3. The data recorded shall not be used for different
purposes which are not compliant with the purpose of collection. Acquaintance with or processing of the data registered in files for a purpose other than the right to enter the
data shall be prohibited. In case data are used to guarantee
national security, public security, for prevention or investigation of a criminal offence, or prosecution of the author
thereof, or of any infringement of ethics for the regulated
professions, it is exempted from this rule.
4. Documentation of the data shall be kept for as long as
it is necessary for the purpose for which they were collected.
5. The security level shall be in compliance with the
nature of personal data processing. Detailed rules on data
security shall be specified by decision of the Commissioner.
6. Procedures for the administering of the data registration, data entry, their processing and disclosure shall be
regulated by a decision of the Commissioner.
31