|
Back-up systems " data kept only for the purpose of replacing other data in the event of their being lost, destroyed or damaged". In order to come within the definition of 'back-up data', data cannot be part of a live system nor can they be used for any purpose other than replacing lost, destroyed or damaged data. What constitutes lost, destroyed or damaged data? What is the purpose of backing-up data? 2(1)(d) "appropriate security measures shall be taken against unauthorised access to, or unauthorised alteration, disclosure or destruction of, the data.." By backing-up data, a data controller/processor is taking steps to recover from such actions. In general, back-ups are most useful in a disaster recovery situation, where there has been a catastrophic system failure resulting in a large scale, if not total loss or corruption of data. For how long should back-up data be held? » Nasc Buan |
|||
|
|||