10 Chapter 7 — Data security and storage of personal data Section 32 — Data security (1) The controller shall carry out the technical and organisational measures necessary for securing personal data against unauthorised access, against accidental or unlawful destruction, manipulation, disclosure and transfer and against other unlawful processing. The techniques available, the associated costs, the quality, quantity and age of the data, as well as the significance of the processing to the protection of privacy shall be taken into account when carrying out the measures. (2) Anyone who as an independent trader or business operates on the behalf of the controller shall, before starting the processing of data, provide the controller with appropriate commitments and other adequate guarantees of the security of the data as provided in paragraph (1). Section 33 — Secrecy obligation Anyone who has gained knowledge of the characteristics, personal circumstances or economic situation of another person while carrying out measures relating to data processing shall not disclose the data to a third person against the provisions of this Act. Section 34 — Destruction of a personal data file If a personal data file is no longer necessary for the operations of the controller, it shall be destroyed, unless specific provisions have been issued by an Act or by lower-level regulation on the continued storage of the data contained therein or the file is transferred to be archived in accordance with section 35. Section 35 — Transfer of personal data to be archived (1) Separate provisions apply to the use and protection of personal data files which have been transferred to the possession of the archive authorities, as well as to the disclosure of data from such files. However, when disclosing personal data from a private file, the archive authority shall take into account the provisions in this Act on the processing and disclosure of personal data, unless this, in view of the age or nature of the data recorded in the file, is manifestly unnecessary for the protection of the privacy of the data subjects. (2) A personal data file which is significant for purposes of scientific research or otherwise may be transferred for archiving to an institution of higher education or to a research institute or authority operating on a statutory basis, where the National Archives have granted a permission for such archiving. The National Archives may grant corporations, foundations and institutions a permission to archive personal data files compiled in their own activities and fulfilling the requirements above. In the permission the National Archives shall lay down rules for the protection of the files and for the monitoring of the use of the personal data. (3) Before granting a permission referred to in paragraph (2). the National Archives shall reserve the Data Protection Ombudsman an opportunity to issue an opinion on the matter. Chapter 8 — Notification to the Data Protection Ombudsman Section 36 — Duty of notification (1) The controller shall notify the Data Protection Ombudsman of automated data processing by sending a description of the file to that authority. (2) In addition, the controller shall notify the Data Protection Ombudsman of: (1) the transfer of personal data to outside the European Union or the European Economic Area, if the data are transferred on the grounds provided in section 22 or 23(6) or (7) and there is no statutory provision on the same; or (2) the launching of an automated decision-making system referred to in section 31. (3) Anyone who is engaged in credit data activity or carrying out debt collection or market or opinion research as a business, or operating in recruitment, personnel assessment or computing on the behalf of another, and who uses or processes files or personal data in this activity, shall

Select target paragraph3