25.01.2018 Views

white_paper_on_data_protection_in_india_171127_final_v2

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

South Africa<br />

The POPI Act specifies that pers<strong>on</strong>al <strong>in</strong>formati<strong>on</strong> must be collected for a specific, explicitly<br />

def<strong>in</strong>ed and lawful purpose related to the activity of the collect<strong>in</strong>g party. 496 With respect to<br />

further process<strong>in</strong>g of pers<strong>on</strong>al <strong>in</strong>formati<strong>on</strong>, it must be compatible with the purposes for which<br />

it was collected. The test for compatibility would take <strong>in</strong>to account factors such as the nature<br />

of the <strong>in</strong>formati<strong>on</strong> collected, the c<strong>on</strong>sequences of the <strong>in</strong>tended process<strong>in</strong>g to the <strong>data</strong> subject,<br />

etc. This Act also specifies certa<strong>in</strong> c<strong>on</strong>diti<strong>on</strong>s under which further process<strong>in</strong>g of <strong>in</strong>formati<strong>on</strong><br />

will not be c<strong>on</strong>sidered <strong>in</strong>compatible. 497<br />

Australia<br />

Under the Privacy Act, c<strong>on</strong>sent is not required for the collecti<strong>on</strong> of pers<strong>on</strong>al <strong>in</strong>formati<strong>on</strong>.<br />

However, the collecti<strong>on</strong> of pers<strong>on</strong>al <strong>in</strong>formati<strong>on</strong> must be reas<strong>on</strong>ably c<strong>on</strong>nected to the activity<br />

of the collect<strong>in</strong>g entity. The APPs provide that an entity under the Privacy Act can <strong>on</strong>ly use<br />

or disclose pers<strong>on</strong>al <strong>in</strong>formati<strong>on</strong> for a purpose for which it was collected (known as the<br />

primary purpose), or for a sec<strong>on</strong>dary purpose if an excepti<strong>on</strong> applies. These excepti<strong>on</strong>s<br />

<strong>in</strong>clude: (i) where the <strong>in</strong>dividual has c<strong>on</strong>sented to a sec<strong>on</strong>dary use 498 ; (ii) the <strong>in</strong>dividual<br />

reas<strong>on</strong>ably expects the entity to use or disclose her pers<strong>on</strong>al <strong>in</strong>formati<strong>on</strong> for the sec<strong>on</strong>dary<br />

purpose, which must be related to the primary purpose 499 ; (iii) if the sec<strong>on</strong>dary use/disclosure<br />

is required or authorised by law 500 ; (iv) if there is a permitted general situati<strong>on</strong> which exists <strong>in</strong><br />

relati<strong>on</strong> to the sec<strong>on</strong>dary use or disclosure, such as permitted situati<strong>on</strong>s relat<strong>in</strong>g to<br />

enforcement activities. 501<br />

The reas<strong>on</strong>ableness test relies <strong>on</strong> whether a reas<strong>on</strong>able pers<strong>on</strong> who is properly <strong>in</strong>formed,<br />

would expect such a use of pers<strong>on</strong>al <strong>data</strong> <strong>in</strong> the circumstances. This is a questi<strong>on</strong> of fact <strong>in</strong><br />

each <strong>in</strong>dividual case and it is the resp<strong>on</strong>sibility of the entity to justify its c<strong>on</strong>duct. For<br />

example, an employee of a company would reas<strong>on</strong>ably expect it to use her bank account<br />

<strong>in</strong>formati<strong>on</strong> <strong>in</strong> order to process salary payments. 502 However, she would not reas<strong>on</strong>ably<br />

expect the company to disclose her salary statement to an advertis<strong>in</strong>g company.<br />

The OAIC has recognised the <strong>in</strong>compatibility of purpose limitati<strong>on</strong> and use specificati<strong>on</strong> with<br />

current developments <strong>in</strong> Big Data analytics, a c<strong>on</strong>sultati<strong>on</strong> draft published <strong>in</strong> 2016 suggests<br />

that privacy impact assessments (described <strong>in</strong> the chapter <strong>on</strong> notice, above) be carried out to<br />

496 Secti<strong>on</strong> 13, POPI Act.<br />

497 Secti<strong>on</strong>s 14 and 15, POPI Act.<br />

498 APP 6.1(a), Privacy Act.<br />

499 APP 6.2 (a), Privacy Act.<br />

500 APP 6.2(b), Privacy Act.<br />

501 APPs 6.2(e) and 6.3, Privacy Act.<br />

502 OAIC, ‗Chapter 6: Australian Privacy Pr<strong>in</strong>ciple 6 — Use or disclosure of pers<strong>on</strong>al <strong>in</strong>formati<strong>on</strong>‘ (February<br />

2014), available at: https://www.oaic.gov.au/resources/agencies-and-organisati<strong>on</strong>s/app-guidel<strong>in</strong>es/chapter-6-<br />

app-guidel<strong>in</strong>es-v1.pdf, (last accessed 23 October 2017).<br />

108

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!