Chapter II Section 7 establishes data security obligations. Controller and processor shall apply appropriate technical + organisational measures + procedures to protect personal data and the privacy rights of data subjects. Considerations: state of the art + costs + nature + scope + context + purposes + risks (similar to GDPR Article 32 but adapted to Hungarian terminology). Specific measures: prevention of unauthorised access + unauthorised disclosure + accidental + intentional erasure + alteration + loss + accidental access of unauthorised persons. Encryption + pseudonymisation + access controls + audit logs + backup + incident response + secure transmission. Section 25 onwards (Sections 25A-25K added by 2018 GDPR Implementation Act) cover: Section 25A controller obligations + Section 25B Data Protection Officer obligations + Section 25C records of processing + Section 25D security + Section 25E Data Protection Impact Assessment + Section 25F prior consultation + Section 25G data breach notification (72 hours to NAIH + without undue delay to high-risk affected data subjects) + Section 25H processor obligations + Section 25I joint controllers + Section 25J certification + Section 25K codes of conduct. NAIH expects data breach via online form within 72 hours. HU Infotv Section 7 + Section 25 GDPR-aligned + processor + joint controllers + 72-hour breach + DPIA + NAIH applies.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.