Section 55 | Overview and scope
From legislation.gov.uk
(1)This Chapter—
(a)sets out the general obligations of controllers and processors (see sections to );
(b)sets out specific obligations of controllers and processors with respect to security (see );
(c)sets out specific obligations of controllers and processors with respect to personal data breaches (see sections and );
(d)makes provision for the designation, position and tasks of data protection officers (see sections to );
(e)makes provision about codes of conduct (see ).F1
(2)This Chapter applies only in relation to the processing of personal data for a law enforcement purpose.
(3)Where a controller is required by any provision of this Chapter to implement appropriate technical and organisational measures, the controller must (in deciding what measures are appropriate) take into account—
(a)the latest developments in technology,
(b)the cost of implementation,
(c)the nature, scope, context and purposes of processing, and
(d)the risks for the rights and freedoms of individuals arising from the processing.