Data Protection in the British Virgin Islands

Security in the British Virgin Islands

While the DPA does not specify any technical standards for data controllers to implement, the DPA requires a data controller, when processing personal data, to take practical steps to protect the personal data from any loss, misuse, modification, unauthorized or accidental access, or disclosure, alteration or destruction (together, 'Security Breach') by having regard to the following matters:

  • the nature of the personal data and the harm that would result from a Security Breach
  • the place or location where the personal data is stored
  • any security measures incorporated into any equipment in which the personal data is stored
  • the measures taken for ensuring the reliability, integrity, and competence of personnel having access to the personal data, and
  • the measures taken for ensuring the secure transfer of the personal data

The DPA also requires, where a data processor carries out the processing of personal data on behalf of the data controller, the data controller (for the purpose of protecting the personal data from Security Breach) to ensure that the data processor:

  • provides sufficient guarantees in respect of the technical and organisational security measures governing the processing to be carried out, and
  • take reasonable steps to ensure compliance with the above measures

Continue reading

  • no results

Previous topic
Back to top