Processed for Specified, Explicit and Legitimate Purposes

Questions

  • No
  • Yes
  • Not Applicable

Recommended Actions

An organisation should only process personal data for the specific purposes explained to data subjects (or for other purposes expressly permitted by GDPR). The purposes for which an organisation processes personal data must be informed to data subjects at the time that their personal data is collected, where it is collected directly from them, or as soon as possible (not more than one calendar month) after collection where it is obtained from a third party.

  • Completed
  • Not Applicable
  • In Progress