Art. 55 - (vetoed)Art. 56 - (vetoed)Art. 57 - (vetoed)Art. 58 - (vetoed)Art. 59 - (vetoed)
VII – security: use of technical and administrative measures which are able to protect personal data from unauthorised accesses and accidental or unlawful situations of destruction, loss, alteration, communication or dissemination; VIII – prevention: adoption of measures to prevent the occurrence of damages due to the processing of personal data;
X – accountability: demonstration by the agent of the adoption of measures which are efficient and capable of proving the compliance with the rules of personal data protection, including the efficacy of such measures.
§2 The controller shall adopt measures to ensure transparency of data processing based on her/his legitimate interests.
§4 If it is impossible to immediately adopt the measure mentioned in §3 of this article, the controller shall send a reply to the data subject in which she/he may:
II – indicate the reasons of fact or of law that prevent the immediate adoption of the measure.
The national authority may request agents of the public authorities to publish impact reports on protection of personal data and may suggest the adoption of standards and good practices for processing personal data by the public authorities.
IV – the adoption of security measures as provided in regulation;
§5 Guarantees sufficient for compliance with the general principles of protection and data subject’s rights referred to in the lead sentence of this article shall also be analysed in accordance with the technical and organisational measures adopted by the processor, according to the provisions of §§1 and 2 of Art. 46 of this Law.
The national authority may determine that the controller must prepare an impact report on protection of personal data, including sensitive data, referring to its data processing operations, pursuant to regulations, subject to commercial and industrial secrecy. Sole paragraph. Subject to the provisions of the lead sentence of this article, the report must contain at least a description of the types of data collected, the methodology used for collection and for ensuring the security of the information, and the analysis of the controller regarding the adopted measures, safeguards and mechanisms of risk mitigation.
The controller shall appoint an officer to be in charge of processing personal data. §1 The identity and contact information of the officer shall be publicly disclosed, in a clear and objective manner, preferably on the controller’s website. §2 Officer’s activities consist of: I – accepting complaints and communications from data subjects, providing explanations and adopting measures; II – receiving communications from the national authority and adopting measures; III – orienting entity’s employees and contractors regarding practices to be taken in relation to personal data protection; and IV – carrying out other duties as determined by the controller or set forth in complementary rules. §3 The national authority may establish complementary rules about the definition and the duties of the officer, including situations in which the appointment of such person may be waived, according to the nature and the size of the entity or the volume of data processing operations.
III – the techniques for processing personal data available at the time it was done. Sole paragraph. The controller or the processor who neglect to adopt the security measures provided in Art. 46 of this Law shall be held liable for the damages caused by the violation of the security of the data that caused the damage.
Processing agents shall adopt security, technical and administrative measures able to protect personal data from unauthorised accesses and accidental or unlawful situations of destruction, loss, alteration, communication or any type of improper or unlawful processing.
VI – the measures that were or will be adopted to reverse or mitigate the effects of the damage.
§2 The national authority shall verify the seriousness of the incident and may, if necessary to safeguard the data subjects’ rights, order the controller to adopt measures, such as:
§3 When judging the severity of the incident, eventual demonstration that adequate technical measures were adopted to render the affected personal data unintelligible will be analysed, within the scope and the technical limits of the services, to third parties who were not authorised to access them.
a) demonstrate the controller’s commitment to adopt internal processes and policies that ensure broad compliance with rules and good practices regarding the protection of personal data;
The national authority shall encourage the adoption of technical standards that facilitate data subjects’ control of their personal data.
I – warning, with an indication of the time period for adopting corrective measures;
VIII – repeated and demonstrated adoption of internal mechanisms and procedures capable of minimising the damage, for secure and proper data processing, in accordance with the provisions of Item II of §2 of Art. 48 of this Law.
IX – adoption of a good practice and governance policy; X – the prompt adoption of corrective measures; and
§2 The regulation of sanctions and corresponding methodologies shall establish the circumstances and conditions for adopting simple or daily fines.