Name of regulation | ||
---|---|---|
Processing for a purpose other than that for which the personal data have been collected originally | ||
Citation | ||
Where the processing for a purpose other than that for which the personal data have been collected is not based on the data subject's consent or on a Union or Member State law which constitutes a necessary and proportionate measure in a democratic society to safeguard the objectives referred to in Article 23(1), the controller shall, in order to ascertain whether processing for another purpose is compatible with the purpose for which the personal data are initially collected, take into account, inter alia: (a) any link between the purposes for which the personal data have been collected and the purposes of the intended further processing; (b) the context in which the personal data have been collected, in particular regarding the relationship between data subjects and the controller; (c) the nature of the personal data, in particular whether special categories of personal data are processed, pursuant to Article 9, or whether personal data related to criminal convictions and offences are processed, pursuant to Article 10; (d) the possible consequences of the intended further processing for data subjects; (e) the existence of appropriate safeguards, which may include encryption or pseudonymisation. |
||
Legislative localisation | Chapter II, Article 6, Paragraph 4 | |
Regulation's subject matter | Lawfulness of processing (Article 6, Chapter II) | |
Regulation category |
Obligation
|
|
Regulation subcategory |
Prescriptive obligation
|
|
Actors concerned | ||
Obligation | Controller |
|
Related actors | Data subject European Union Member state |
|
Knowww link | https://knowww.eu/nodes/5a0595ea4b5b5f00019038c4 |