25.01.2018 Views

white_paper_on_data_protection_in_india_171127_final_v2

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

collected for more than <strong>on</strong>e purpose, which are dist<strong>in</strong>ct but related <strong>in</strong> some degree. Privacy<br />

notices attempt to work around this difficulty by us<strong>in</strong>g terms such as ―improv<strong>in</strong>g user<br />

experience‖, ―IT-security purposes‖ and so <strong>on</strong>. These are vaguely worded and the <strong>in</strong>dividual<br />

may not understand the exact purpose for which her <strong>in</strong>formati<strong>on</strong> is be<strong>in</strong>g used. Companies<br />

may also use vague purposes deliberately to allow for the <strong>data</strong> to be put to significantly<br />

higher and varied uses than the <strong>data</strong> subject is likely to th<strong>in</strong>k of. On the other hand, provid<strong>in</strong>g<br />

a detailed descripti<strong>on</strong> full of legal terms may prove counter-productive as it adds to the<br />

complexity of the notice, and makes it difficult for the <strong>in</strong>dividual to read and understand. 492<br />

5.3 Internati<strong>on</strong>al Practices<br />

European Uni<strong>on</strong><br />

The pr<strong>in</strong>ciple of purpose specificati<strong>on</strong> as envisaged under the EU GDPR requires that the <strong>data</strong><br />

c<strong>on</strong>troller must <strong>on</strong>ly collect <strong>data</strong> for specified, explicit and legitimate purposes, and <strong>on</strong>ce the<br />

<strong>data</strong> is collected, it must not be processed further <strong>in</strong> a manner that is <strong>in</strong>compatible with the<br />

orig<strong>in</strong>al purpose. 493 It provides an exempti<strong>on</strong> for further use, as l<strong>on</strong>g as it is for scientific,<br />

historical or statistical research purposes, as they are not c<strong>on</strong>sidered to be <strong>in</strong>compatible<br />

purposes. The <strong>in</strong>tenti<strong>on</strong> beh<strong>in</strong>d us<strong>in</strong>g terms such as ―specified, explicit and limited‖ is to<br />

ensure that the entity collect<strong>in</strong>g the pers<strong>on</strong>al <strong>in</strong>formati<strong>on</strong> carefully c<strong>on</strong>siders what purposes<br />

the <strong>in</strong>formati<strong>on</strong> will be used for, and to avoid the excessive collecti<strong>on</strong> of <strong>in</strong>formati<strong>on</strong> which<br />

may not be necessary, adequate or relevant for the purpose which is <strong>in</strong>tended to be<br />

satisfied. 494 The EU GDPR does not separately provide for the use limitati<strong>on</strong> pr<strong>in</strong>ciple; it is<br />

folded <strong>in</strong>to the purpose specificati<strong>on</strong> pr<strong>in</strong>ciple.<br />

United K<strong>in</strong>gdom<br />

Under the UK DPA, pers<strong>on</strong>al <strong>data</strong> is allowed to be obta<strong>in</strong>ed <strong>on</strong>ly for <strong>on</strong>e or more specified<br />

and lawful purposes and must not be further processed <strong>in</strong> any manner <strong>in</strong>compatible with that<br />

purpose. 495 Additi<strong>on</strong>ally, the UK DPA also provides that the pers<strong>on</strong>al <strong>data</strong> collected should be<br />

adequate, relevant and not excessive <strong>in</strong> relati<strong>on</strong> to the purpose for which it is processed. The<br />

ICO guidel<strong>in</strong>es provide that compatibility of subsequent use depends <strong>on</strong> whether the <strong>in</strong>tended<br />

use can be c<strong>on</strong>sidered lawful under the UK DPA. The purpose specificati<strong>on</strong> pr<strong>in</strong>ciple ensures<br />

that organisati<strong>on</strong>s are open about their reas<strong>on</strong>s for obta<strong>in</strong><strong>in</strong>g pers<strong>on</strong>al <strong>data</strong> and that what they<br />

do with the <strong>in</strong>formati<strong>on</strong> is <strong>in</strong> l<strong>in</strong>e with the reas<strong>on</strong>able expectati<strong>on</strong>s of the c<strong>on</strong>cerned<br />

<strong>in</strong>dividuals.<br />

492 Article 29 Data Protecti<strong>on</strong> Work<strong>in</strong>g Party, ‗Op<strong>in</strong>i<strong>on</strong> 03/2013 <strong>on</strong> purpose limitati<strong>on</strong>‘, European Commissi<strong>on</strong><br />

(2 April 2013) available at: http://ec.europa.eu/justice/<strong>data</strong>-protecti<strong>on</strong>/article-29/documentati<strong>on</strong>/op<strong>in</strong>i<strong>on</strong>recommendati<strong>on</strong>/files/2013/wp203_en.pdf,<br />

(last accessed 24 October 2017).<br />

493 Article 29 Data Protecti<strong>on</strong> Work<strong>in</strong>g Party, ‗Op<strong>in</strong>i<strong>on</strong> 03/2013 <strong>on</strong> purpose limitati<strong>on</strong>‘, European Commissi<strong>on</strong><br />

(2 April 2013) available at: http://ec.europa.eu/justice/<strong>data</strong>-protecti<strong>on</strong>/article-29/documentati<strong>on</strong>/op<strong>in</strong>i<strong>on</strong>recommendati<strong>on</strong>/files/2013/wp203_en.pdf,<br />

(last accessed 24 October 2017).<br />

494 Article 29 Data Protecti<strong>on</strong> Work<strong>in</strong>g Party, ‗Op<strong>in</strong>i<strong>on</strong> 03/2013 <strong>on</strong> purpose limitati<strong>on</strong>‘, European Commissi<strong>on</strong><br />

(2 April 2013) available at: http://ec.europa.eu/justice/<strong>data</strong>-protecti<strong>on</strong>/article-29/documentati<strong>on</strong>/op<strong>in</strong>i<strong>on</strong>recommendati<strong>on</strong>/files/2013/wp203_en.pdf,<br />

(last accessed 24 October 2017).<br />

495 Paragraphs 2 and 3, Schedule 1, UK DPA.<br />

107

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!