ImplementingRegulationPersonalDataProtectionLaw · Table (p.7)
From ImplementingRegulationPersonalDataProtectionLaw.pdf · page 7
| 0 | 1 | 2 | 3 | 4 | 5 | 6 | 7 |
|---|---|---|---|---|---|---|---|
| ! | |||||||
| Article 9: Anonymisation | |||||||
| 1- When a Controller anonymizes the Personal Data of a Data Subject, it shall comply | |||||||
| with the following: | |||||||
| a) Ensure that re-identification of the Data Subject is impossible after Anonymisation. | |||||||
| b) Evaluate the impact, including the possibility of re-identifying | the Data Subject, in | ||||||
| the circumstances specified in Paragraph (1) of Article 25 of this Regulation. | |||||||
| c) Take the necessary organizational, administrative, and technical measures to avoid | |||||||
| risks, | taking | into account | technological | developments | and methods of | ||
| Anonymisation, and update those methods considering such developments. | |||||||
| d) Evaluate | the | effectiveness | of | the | applied | techniques | for Personal Data |
| Anonymization and make necessary adjustments to ensure that re-identification of | |||||||
| Data Subject is impossible. |
Source Metadata