Section 28(3)
DPA 2018
Data Protection Act 2018 · United Kingdom
Where Article 32 of the UK GDPR does not apply, the controller or the processor must implement security measures appropriate to the risks arising from the processing of the personal data.
← 2 · All articles · 4 →
Source: legislation.gov.uk · retrieved 2026-09-04