Section 5(1A)
The measures referred to in paragraph (1) shall at least— ensure that personal data can be accessed only by authorised personnel for legally authorised purposes; protect personal data stored or transmitted against accidental or unlawful destruction, accidental loss or alteration, and unauthorised or unlawful storage, processing, access or disclosure; and ensure the implementation of a security policy with respect to the processing of personal data.
← 1 · All articles · 2 →
Source: legislation.gov.uk · retrieved 2026-09-04