Personal information is collected consistent with the entity’s objectives related to privacy.
Points of focus:
- Limits the Collection of Personal Information
- Collects Information by Fair and Lawful Means
- Collects Information From Reliable Sources
- Informs Data Subjects When Additional Information Is Acquired
Processing of personal data is only lawful if one of the legal bases set out in the General Data Protection Regulation is met. The organization must be able to communicate the purpose of the processing and the legal basis to the data subject and, where appropriate, to the supervisory authority.
The documentation shall include at least:
Understanding data sources is important for understanding data flow. In addition, data protection communications shall be able to communicate the sources of personal data in cases where the data have not been collected directly from the data subject himself.
The organisation ensures that the processing of personal data is necessary and proportionate for the legitimate purposes of the processing. Personal data should only be processed if the purpose of the processing cannot be reasonably achieved by other means.
The implementation of this principle should be regularly verified from a holistic perspective by analysing the documentation of the management system (in particular the purposes for which the data are used).