Each controller must implement appropriate technical and organisational measures which are designed—
The duty under subsection (1) applies both at the time of the determination of the means of processing the data and at the time of the processing itself.
Each controller must implement appropriate technical and organisational measures for ensuring that, by default, only personal data which is necessary for each specific purpose of the processing is processed.
The duty under subsection (3) applies to—
In particular, the measures implemented to comply with the duty under subsection (3) must ensure that, by default, personal data is not made accessible to an indefinite number of people without an individual's intervention.