1.
Member States shall provide that the controller must implement appropriate technical and organizational measures to protect personal data against accidental or unlawful destruction or accidental loss, alteration, unauthorized disclosure or access, in particular where the processing involves the transmission of data over a network, and against all other unlawful forms of processing. Having regard to the state of the art and the cost of their implementation, such measures shall ensure a level of security appropriate to the risks represented by the processing and the nature of the data to be protected.
1 national measure recorded under this provision, in 1 form — sign in to view the analysis.
← art_17__para · All articles · 2. →
Source: EUR-Lex (Cellar) · retrieved 2026-10-09 · Text as adopted (Official Journal); later amendments are not incorporated in this text.