2° supervise the compliance with these measures, in particular by laying them down in
contractual stipulations;
3° lay down in the contract the responsibility of the processor in respect to the controller;
4° agree with the processor that the processor only acts on behalf of the controller and that
the processor is bound by the same obligations as by which the controller is bound pursuant
to paragraph 3;
5° lay down in writing or on electronic carrier the elements of the contract with regard to the
protection of data and the requirements with regard to the measures referred to in paragraph
3.
§ 2. The controller or, if such is the case, his representative in Belgium, shall:
1° watch carefully that the data are updated, that inaccurate, incomplete and irrelevant data,
as well as data that have been obtained or further processed in violation of the Articles 4 to 8,
are corrected or erased;
2° take care that the access to the data and possibilities of processing for the persons who
are acting under his authority, are limited to what is necessary for the fulfilment of their duties
or for the requirements of the service;
3° notify all persons acting under his authority about the provisions of this law and its
implementing decrees, as well as about all relevant provisions in respect of the protection of
the privacy with regard to the processing of personal data;
4° ascertain that the programmes for the automatic processing of personal data are in
accordance with the statements in the notification referred to in Article 17 and that no unlawful
use is made thereof.
§ 3. Any person acting under the authority of the controller or of the processor, as well as the
processor himself having access to the personal data, may only process them on the
instructions of the controller, except for the case of an obligation imposed by or by virtue of a
law, decree or ordinance.
§ 4. In order to guarantee the security of personal data the controller or, if such is the case,
his representative in Belgium, as well as the processor shall take the appropriate technical
and organisational measures that are necessary for the protection of personal data against
accidental or unauthorised destruction, accidental loss, as well as against alteration of,
access to and any other unauthorised processing of personal data.
These measures shall ensure an appropriate level of security taking into account the state of
the art in this field and the cost of implementing the measures on the one hand, and the
nature of the data to be protected and the potential risks on the other hand.
On the advice of the Commission for the protection of privacy the King may promulgate
appropriate standards in the matter of informatics security for all or certain categories of
processing.
Chapter V - Prior notification and public nature of the processing.
Article 17
§ 1. Before carrying out any wholly or partly automatic processing operation or set of such
operations intended to serve a single purpose or several related purposes the controller or, if
13