[भाग II- ख ड 3(i)]
(iii)
(iv)
(v)
भारत का राजप
: असाधारण
purpose of collection and usage of such information;
disclosure of information including sensitive personal data or information as
provided in rule 6;
reasonable security practices and procedures as provided under rule 8.
5. Collection of information.— (1) Body corporate or any person on its behalf shall
obtain consent in writing through letter or Fax or email from the provider of the sensitive
personal data or information regarding purpose of usage before collection of such
information.
(2) Body corporate or any person on its behalf shall not collect sensitive
personal data or information unless —
(a) the information is collected for a lawful purpose connected with a function or
activity of the body corporate or any person on its behalf; and
(b) the collection of the sensitive personal data or information is considered
necessary for that purpose.
(3) While collecting information directly from the person concerned, the body
corporate or any person on its behalf snail take such steps as are, in the
circumstances, reasonable to ensure that the person concerned is having the
knowledge of —
(a) the fact that the information is being collected;
(b) the purpose for which the information is being collected;
(c) the intended recipients of the information; and
(d) the name and address of —
(i) the agency that is collecting the information; and
(ii) the agency that will retain the information.
(4) Body corporate or any person on its behalf holding sensitive personal data
or information shall not retain that information for longer than is required for the
purposes for which the information may lawfully be used or is otherwise required under
any other law for the time being in force..
(5) The information collected shall be used for the purpose for which it has
been collected.
(6) Body corporate or any person on its behalf permit the providers of
information, as and when requested by them, to review the information they had
provided and ensure that any personal information or sensitive personal data or
information found to be inaccurate or deficient shall be corrected or amended as
feasible:
Provided that a body corporate shall not be responsible for the authenticity of the
personal information or sensitive personal data or information supplied by
1330 GI/11-2A