1. The Controller and the Processor shall develop and take appropriate technical and regulatory measures to ensure the highest standard of information security that is suitable for the risks related to data processing in accordance with the best international practices and standards. This shall include the following: a. Encryption of Personal Data and the application of Pseudonymisation. b. Applying measures which ensure the continuous confidentiality, safety, accuracy and flexibility of data processing systems and services. c. Applying measures which ensure timely retrieval of and access to Personal Data in case of any actual or technical failure. d. Applying measures which ensure a seamless testing and evaluation of the effectiveness of the technical and regulatory measures to ensure the security of processing. 2. When evaluating the information security level as set out in Paragraph1 of this Article, the following shall be observed: a. Data processing risks, including damage, loss, accidental or illegal change and disclosure of or access to the Personal Data, whether being transferred, stored or processing. b. The costs of data processing, and its nature, scope and purposes, in addition to potential risks impacting the confidentiality and privacy of the Data Subject's Personal Data.
Interpretation and application must be checked against the official text and current version.
