Security Principle Sample Clauses

Security Principle. The Data Receiver shall take necessary technical and managerial measures to ensure the security of personal data, preventing data leakage, misuse, or illegal access.
Security Principle a) The Data Importer and, during the transfer, also the Data Exporter shall establish and maintain administrative, physical and technical Measures sufficient to ensure the confidentiality, integrity and availability of the Personal Data covered by this Agreement; in particular, protection against Personal Data Security Breaches. In determining an appropriate level of security, the parties shall take due account of the state of the art, the costs of implementation, the nature, scope, context and purposes of the processing, and the risks posed by the processing to the Data Subjects. In fulfilling its obligations under this paragraph, the Data Importer shall implement, at a minimum, the administrative, physical and technical Measures set out in Annex C to this Agreement. The Data Importer shall carry out periodic checks to ensure that these measures continue to provide an adequate level of security. b) In the event of a breach of security of Personal Data processed by the Data Importer under this Agreement, the Data Importer shall take appropriate measures to remedy the breach and, in particular, measures to mitigate the adverse effects. c) The Data Importer shall also notify the Data Exporter within seventy-two (72) hours of becoming aware of the Security Breach. Such notification shall include a description of the nature of the Breach (including, where possible, the categories and approximate number of Data Subjects and Personal Data records affected), the likely consequences, and the measures taken or proposed to remedy the Security Breach, including, where appropriate, measures to mitigate its possible adverse effects. d) When and to the extent that all information cannot be provided at the same time, the initial notification shall provide the information currently available and, as it becomes available, additional information shall be provided without undue delay. e) The Data Importer shall cooperate with the Data Exporter and assist the Data Exporter in fulfilling its obligations under the applicable Law, especially as regards notification to the competent Supervisory Authority and to the Data Subjects concerned, taking into account the nature of the processing and the information available to the Data Importer.