Menu

Filter by
content
PONT Data&Privacy

0

Article 4a (data protection by security and design)

  • 1

    The controller and processor shall take appropriate technical and organizational measures to:

    • a.

      ensure and be able to demonstrate that the processing of police data is carried out in accordance with the provisions of or under this Act;

    • b.

      Effectively implement and apply data protection policies and principles respectively;

    • c.

      in determining the means of processing and the processing itself, build into the processing the necessary safeguards, such as pseudonymization, to comply with what is provided by or under this Act and to protect the rights of data subjects.

  • 2

    The controller and the processor shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, in particular in relation to the processing of the special categories of police data referred to in Article 5, and in such a way that the police data are protected against unauthorized or unlawful processing and against intentional loss, destruction or damage.

  • 3

    When implementing the measures referred to in the first and second paragraphs, the controller and the processor shall take into account the nature, scope, context and purposes of the processing, as well as the risks to the rights and freedoms of natural persons which vary in their likelihood and gravity.

  • 4

    In addition to the third paragraph, with respect to the first paragraph (c) and the second paragraph, the controller and the processor shall take into account the state of the art and implementation costs.

  • 5

    The measures referred to in the first and second paragraphs shall be periodically reviewed and, if necessary, updated.

  • 6

    Further rules on the measures referred to in paragraphs 1 and 2 shall be laid down by or pursuant to an order in council.

Information valid on 01-01-2020

Regulations based on this article (delegated regulations)

  1. Decree implementing data protection directive detection and prosecution

Policies and circulars that have this article as legal authority

No

Articles or similar text referring to this article

  1. Decree implementing data protection directive detection and prosecution

  2. Police Data Decree
    article: 6:1a

  3. Penalty Policies Autoriteit Persoonsgegevens 2019
    annex: 5

  4. Regulation WPG Defense
    article: 6.2

  5. Law on use of passenger data to combat terrorist and serious crimes
    Article: 17

  6. Police Data Act
    article: 31d, 35c, 36c, 1

  7. Money Laundering and Terrorist Financing Prevention Act
    section: 14

Summary of changes for this article

(01-01-2020)

Origination source

Entry into force

Effective date

Retroactivity

Subject

Signature

Announcement

Chamber documents

Signature

Announcement

Note

2019

new

2018

Stb. 2018, 401

34889

2018

Stb. 2018, 495