Section 28(4)
For the purposes of subsection (3), where the processing of personal data is carried out wholly or partly by automated means, the controller or the processor must, following an evaluation of the risks, implement measures designed to— prevent unauthorised processing or unauthorised interference with the systems used in connection with the processing, ensure that it is possible to establish the precise details of any processing that takes place, ensure that any systems used in connection with the processing function properly and may, in the case of interruption, be restored, and ensure that stored personal data cannot be corrupted if a system used in connection with the processing malfunctions.
← 3 · All articles · 5 →
Source: legislation.gov.uk · retrieved 2026-09-04