No. 3
9
Data Protection
(ii) a legal requirement or obligation of the data controller or
data processor;
(iii) necessary in order to protect vital interests of the data
subject or another natural person;
(iv) authorized by a written law and carried out by a
competent public authority in furtherance of its legal mandate;
(v) required by, or under, any written law or an order of a
court of law;
(vi) necessary for the performance of a task carried out in the
public interest or in the exercise of official authority vested in
the data controller or data processor; or
(vii) necessary for the purpose of a legitimate interest
pursued by the data controller or data processor or by a third
party to whom the data is disclosed, except where the interest
of the data controller or data processor or third party is
overridden by the interest of a fundamental right or freedom of
a data subject.
9.__(1) a data controller and data processor shall collect personal
data for a specific and legitimate purpose and shall not process the
data in a manner that is incompatible with the purpose for which it
was collected.
(2) a data controller or data processor who intends to process
personal data for a purpose other than the purpose for which the data
was originally collected, shall ascertain whether the processing of
the data for the other purpose is compatible with the purpose for
which the data was initially collected.
(3) a data controller or data processor shall, in ascertaining
compatibility under subsection (2), consider—
(a) any linkage between the purpose for which the data was
originally collected and the other purpose for which the data
controller or data processor intends to process the data;
(b) the context in which the data was originally collected, in
particular, having regard to the relationship between a data
subject and the data controller;
(c) the nature of the data to be processed, in particular, having
regard to the sensitivity of the data;
(d) potential consequences of the intended data processing to
the data subject; and
(e) the existence of appropriate safeguards, including
encryption and pseudonymization.
Purpose
limitation