2025-02-18
Added · Updated
These regulations establish a mandatory framework for the National Database and Registration Authority to protect sensitive data through defined information security policies, access controls, and incident management protocols. The document mandates the appointment of Data Protection Officers and Chief Information Security Officers to oversee compliance, regular auditing, and organizational risk management. It further imposes strict security obligations on third-party service providers and requesting entities, requiring legally binding data-sharing agreements and continuous monitoring to ensure the integrity, availability, and confidentiality of all citizen data.