Tonga Privacy Act 2025
Part III: obligations of data controllers and data processors – Tonga Privacy Act 2025

Tonga Privacy Act 2025 s36: s.36 Secure personal information with risk-based technical and organisational measures

Controllers and processors must protect the security, integrity and confidentiality of personal information against accidental, unauthorised or unlawful loss, misuse, destruction, damage, access or processing, by identifying foreseeable risks, setting and maintaining safeguards, regularly verifying them and updating them for new risks, considering pseudonymisation, encryption, resilience, timely restoration and periodic risk assessment, and having regard to accepted and industry practices, the volume and sensitivity of data, likely harm, extent of processing, retention period and cost relative to size.

Maintained by Gerard Blokdyk

Other controls in Part III: obligations of data controllers and data processors – Tonga Privacy Act 2025

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.