10
Data
minimization
Data accuracy
storage
limitation
Data Protection
No. 3
(4) where a data controller or data processor subsequently
processes personal data, for the purpose of archiving the data for
public interest or for research or statistical purposes, the subsequent
processing of the data shall not be considered to be incompatible
with the original purpose for which the data was collected.
10. a data controller and data processor shall ensure that
personal data intended to be processed by the data controller or data
processor is adequate, relevant and limited to what is necessary for
the purpose for which the data is intended to be processed.
11.__(1) a data controller or data processor shall ensure that the
personal data the data controller or data processor intends to process
is accurate and, where necessary, is up-to-date.
(2) where a data controller or data processor intends to process
personal data and it comes to his or her knowledge that the data is
inaccurate, in relation to the purpose for which it is intended to be
processed, the data controller or data processor shall erase the data
or take steps to rectify the inaccuracy.
12.__(1) a data controller and data processor shall not store
personal data for a period that is longer than the period that is
necessary to achieve the purpose for which the data is processed.
(2) a data controller and data processor may store personal data
for a period longer than the period prescribed under subsection (1)
where the data is stored for the purpose of archiving for public
interest or for research or statistical purposes.
Data integrity
and data
confidentiality
Principles for
determining the
validity of
consent
(3) where the data controller or data processor stores personal
data in accordance with subsection (2), the data controller or data
processor shall ensure that—
(a) the principle of data minimization, as provided under
section 10, is adhered to; and
(b) the personal data is, where appropriate, pseudonymized.
13.__a data controller and data processor shall ensure that the
appropriate technical or organizational security measures are
implemented to guarantee the security of personal data, including
protection against unauthorized or unlawful processing and
accidental loss, destruction, or damage of the data.
14.__(1) a data controller shall—
(a) obtain the consent of a data subject; or
(b) where the data subject is a child or a person who is not
capable of providing consent, obtain the consent of the legal
guardian of the data subject,