Facsimile · p. 3
**First: Principles of Personal Data Protection** 1. **Lawfulness and Transparency of Data:** The processing of personal data must be lawful, fair, and transparent towards the data subject. 2. **Purpose Limitation:** Personal data must be collected for specified, explicit, and legitimate purposes and should not be processed in a manner incompatible with those purposes. 3. **Data Minimization:** Personal data must be adequate, relevant, and limited to what is necessary for the purposes for which it is processed. 4. **Accuracy:** Personal data must be accurate and, where necessary, kept up to date, and all reasonable steps must be taken to ensure that inaccurate data is erased or rectified without delay. 5. **Storage Limitation:** Personal data must be kept in a form which permits the identification of data subjects for no longer than is necessary for the purposes for which the personal data is processed. 6. **Integrity and Confidentiality:** Personal data must be processed in a manner that ensures appropriate security of the personal data, including protection against unauthorized or unlawful processing and against accidental loss, destruction or damage, by using appropriate technical or organizational measures.
**Second: Rights of Data Subjects** Data subjects have, under certain conditions, the following rights: * **Right of Access:** The right to obtain confirmation as to whether or not personal data concerning him or her is being processed, and the right to access that data. * **Right to Rectification:** The right to request the rectification of inaccurate personal data concerning him or her. * **Right to Erasure (Right to be Forgotten):** The right to request the erasure of personal data concerning him or her in specific cases (e.g., when it is no longer needed). * **Right to Restriction of Processing:** The right to request the restriction of processing of his or her personal data in specific cases. * **Right to Object:** The right to object to the processing of his or her personal data in specific cases. * **Right to Data Portability:** The right to receive his or her personal data, in a structured, commonly used and machine-readable format, and the right to transmit that data to another controller without hindrance.
**Third: Responsibilities of the Data Controller** The data controller is responsible for complying with the principles mentioned above and for taking appropriate measures to ensure compliance, including: * Implementing clear data protection policies and procedures. * Training employees on data protection principles and data subject rights. * Conducting data protection impact assessments when necessary. * Responding to data subject requests concerning their rights in a timely manner. * Reporting data breaches to the competent authorities and data subjects when necessary.