Vehicle Registration Data (Automated Searching and Exchange) Act 2018

Duties of data controllers

9. (1) A data controller—

(a) shall, in relation to the processing of personal data supplied or received under this Act, comply with the technical specifications of an automated search under a European Union instrument or the Agreement, and

(b) shall ensure that the measures provide a level of security appropriate to—

(i) the harm that might result from unauthorised or unlawful processing, accidental or unlawful destruction or accidental loss of, or damage to, or accidental alteration of, the data concerned, and

(ii) the nature of the data concerned.

(2) A data controller shall not use the inaccuracy of personal data received by him or her from a body in a designated state under a European Union instrument or the Agreement as a ground to avoid or reduce his or her liability to the data subject concerned as regards the duty of care owed to the data subject in relation to the collection by him or her of personal data or information intended for inclusion in such data or his or her dealing with such data.

(3) Where the Minister pays damages to a data subject where damage is caused to the data subject by reason of inaccurate data received by the national contact point in the State in relation to vehicle registration data from a body in a designated state under this Act, the Minster may seek a refund of the amount that he or she paid in damages to the data subject concerned from the body in the designated state concerned.

(4) Where a body in a designated state applies to the national contact point in the State in relation to vehicle registration data for a refund of damages paid by it, or on its behalf, on foot of a decision or finding of a court or other tribunal or the data protection authority of that designated state for damage caused to the data subject by reason of inaccurate data sent by the national contact point to that body under this Act, the Minister shall refund to the body in the designated state concerned the amount paid in damages by it, or on its behalf, to the data subject concerned.