MinmumPDGuideline · Table (p.6)
From MinmumPDGuideline.pdf · page 6
| 0 | 1 | 2 | 3 | 4 |
|---|---|---|---|---|
| 1. Actual Need: Each element of Personal Data should be evaluated to | ||||
| determine whether it is directly necessary to achieve the purpose of its | ||||
| collection and processing. | ||||
| 2. Purpose: The purpose for which Personal Data is collected must be directly | ||||
| linked to the data itself and directly relevant to the Controller’s purposes. It | ||||
| must not conflict with the provisions of other applicable regulations in the | ||||
| Kingdom. The Controller must exercise due diligence in achieving the | ||||
| purpose of processing without collecting unnecessary Personal Data. | ||||
| 3. Collection Methods: Personal Data collection methods must be direct, | ||||
| clear, secure, and appropriate to the Data Subject’s circumstances. They | ||||
| must also be free from any means that could lead to deception, misleading, | ||||
| or extortion and must not contravene or conflict with the provisions of | ||||
| applicable regulations in the Kingdom. | ||||
| 4. Content: The content of Personal Data should be adequate and limited to | ||||
| the minimum necessary to achieve the purpose of its collection, whether it | ||||
| is collected directly from the Data Subject or others. If the Controller | ||||
| achieves the purpose of its collection, the content shall not include anything | ||||
| that could lead to the identification of the Data Subject. | ||||
| 5. Destruction: Personal Data that is no longer necessary to achieve the | ||||
| purpose for which it was collected shall be destroyed, following secure | ||||
| procedures to ensure the permanent removal of the data. | ||||
| 6. Retention: The Controller shall retain the minimum amount of Personal Data | ||||
| necessary to achieve the purpose of processing, in addition to restricting | ||||
| logical and physical access | rights | to Personal Data | to | the minimum |
| privileges and actual need. |
Source Metadata