Standard 7 per Section 35 + the Schedule of the Jamaica Data Protection Act 2020: Personal data shall be processed in a manner that ensures appropriate security including protection against unauthorised or unlawful processing + accidental loss + destruction or damage using appropriate technical and organisational measures. (1) Risk-Based Security per Section 35: (a) security measures appropriate to the risk; (b) state of the art consideration; (c) cost of implementation; (d) nature + scope + context + purposes; (e) risk of varying likelihood and severity for data subject rights and freedoms; (f) particular consideration for risks of accidental + unlawful destruction + loss + alteration + unauthorised disclosure or access. (2) Technical Measures: (a) Encryption per Section 35(1)(a) - at-rest + in-transit + in-use; (b) Pseudonymisation - personal data cannot be attributed to specific data subject without additional information kept separately; (c) Access Control - role-based + need-to-know + least privilege + just-in-time; (d) Authentication - multi-factor + strong; (e) Network Security - firewalls + IDS/IPS + segmentation + Zero Trust; (f) Application Security - secure coding + OWASP + SAST/DAST + penetration testing; (g) Database Security - column-level encryption + activity monitoring; (h) Backup + Recovery + tested DR; (i) Endpoint Security + EDR; (j) Cloud Security per CSA CCM + ISO 27017/27018. (3) Organisational Measures: (a) Information Security Policy + signed by senior management; (b) Acceptable Use Policy; (c) Roles + Responsibilities + Segregation of Duties; (d) Training + Awareness program; (e) Background checks; (f) Confidentiality agreements; (g) Vendor + Processor security obligations per Section 26 contracts; (h) Incident Response Plan + tested; (i) Business Continuity Plan; (j) Periodic Risk Assessment + Audit. (4) Confidentiality + Integrity + Availability + Resilience (CIAR): (a) Confidentiality - only authorised parties access; (b) Integrity - data not improperly modified; (c) Availability - data accessible when needed by authorised parties; (d) Resilience - system continues to function under attack or fault. (5) Ability to Restore: (a) backup integrity; (b) ransomware-resistant backups; (c) offsite + air-gapped + immutable; (d) periodic restore testing; (e) RTO + RPO targets; (f) DR exercises. (6) Regular Testing per Section 35(1)(d): (a) regular testing + assessing + evaluating effectiveness; (b) penetration testing - annual + after material change; (c) vulnerability scanning - continuous; (d) red team exercises; (e) tabletop exercises; (f) phishing simulation; (g) incident response drills. (7) Section 28-30 Breach Notification: (a) Section 28 duty to notify Commissioner without undue delay + within 72 hours where feasible; (b) Section 29 information required - nature + categories + numbers + consequences + measures taken; (c) Section 30 notification to data subjects without undue delay where high risk; (d) Cross-Sector cooperation - FSC + BoJ + ICT regulators. (8) Sector-Specific Security Standards: (a) Banking + Insurance per FSC + BoJ Cybersecurity Guidelines; (b) Health per Public Health Act + emerging guidance; (c) Critical Infrastructure protection; (d) Telecommunications per OUR Office of Utilities Regulation. (9) Vendor + Processor Security per Section 26: (a) processor contracts must require equivalent security; (b) processor must not engage sub-processor without authorisation; (c) processor must assist controller in fulfilling obligations; (d) controller liability for processor breach. (10) Penalties for Security Failures: (a) Section 50 administrative penalties up to JMD 10M; (b) Section 31 unauthorised disclosure - up to JMD 4M + 4 years; (c) Section 52 civil compensation. Coordinates with EU GDPR Article 32 + UK DPA 2018 + Convention 108+ Article 7 + ISO/IEC 27001 + 27002 + 27017 + 27018 + 27701 + NIST CSF 2.0 + NIST SP 800-53 + ITU-T X.805 + Jamaica Section 26 Processor + Section 28-30 Breach + FSC + BoJ + OUR. Jamaica DPA 2020 Standard 7 + Section 35 applies.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.