CHAPTER VII SECURITY OF PERSONAL DATA Article 27 Measures for the security of personal data 1. The controller or the processor shall take appropriate organizational and technical measures in order to protect personal data from unlawful or accidental destruction, accidental loss, from access or disclosure to unauthorized persons, especially when the processing of data takes place in a network, as well as from any other unlawful form of processing. 2. The controller shall take the following special security measures: a) defines the functions of the organizational units and those of the operators as regards the use of data; b) data shall be used with the order of authorized organizational units or operators; c) instructs all operators concerning their obligations, in conformity with this law and the internal regulations on data protection, including the regulations on data security; ç) Prohibits access of unauthorized persons to the working facilities of the data controller or processors; d) data and programmes shall be accessed only by authorized persons; dh) Prohibits access to the filing system and their use by unauthorized persons; 30 e) Operation of the data processing equipment shall be carried out upon authorization and every device shall be secured with preventive measures against unauthorized operation; ë) records and documents the alteration, rectification, erasure, transfer, etc. 2.1. The controller is obliged to document the technical and organizational measures adjusted and implemented to ensure protection of personal data in compliance with the law and other legal regulations. 3. The data recorded shall not be used for different purposes which are not compliant with the purpose of collection. Acquaintance with or processing of the data registered in files for a purpose other than the right to enter the data shall be prohibited. In case data are used to guarantee national security, public security, for prevention or investigation of a criminal offence, or prosecution of the author thereof, or of any infringement of ethics for the regulated professions, it is exempted from this rule. 4. Documentation of the data shall be kept for as long as it is necessary for the purpose for which they were collected. 5. The security level shall be in compliance with the nature of personal data processing. Detailed rules on data security shall be specified by decision of the Commissioner. 6. Procedures for the administering of the data registration, data entry, their processing and disclosure shall be regulated by a decision of the Commissioner. 31

Select target paragraph3