|
What
Needs to be Done Prior to Collection
Contact
the data subject
Contact the Commissioner
19.
The
Controller or any other person
authorized
by him in that
capacity must provide a data subject from whom data
relating to the data subject himself
is collected, with at least the following information,
except, where the data subject already has it:
(a) the
identity and habitual residence or principal place of business of
the controller and of any other person
authorised
by him in that behalf, if any;
(b) the
purposes of the processing for which the data
is intended; and
(c) any
further information relating to matters such as:
(i) the recipients
or categories of the recipients of data;
(ii) whether the
reply to any questions made to the data subject is obligatory or
voluntary, as well as the possible consequence of failure to reply;
and
(iii) the
existence of the right to access, the right to rectify, and, where
applicable, the right to erase the data concerning him, and, insofar
as such further information is necessary, having regard to the
specific circumstances in which the data is collected, to guarantee
fair processing in respect of the data subject
Contact the Commissioner
Obligation for
notification
29.
(1) The
controller shall notify the Commissioner before carrying out any
wholly or partially automated processing operation or set of such
operations intended to serve a single purpose or several related
purposes.
(2) The Minister
may prescribe on any matter relating to the form of notification to
be made under this sub article in respect of -
(a)
processing whose sole purpose is the keeping of a register which
according to laws or regulations is intended to provide information
to the public and which is open to consultation either by the public
in general or by any person demonstrating a legitimate interest; and
(b)
processing operations referred to in article 14.
(3) The
notification referred to in sub article (1) must specify:
(a) the
name and address of the data controller and of any other person
authorised
by him in that behalf, if any;
(b) the
purpose or purposes of the processing;
(c) a
description of the category or categories of data subject and of the
data or categories of data relating to them;
(d) the
recipients or categories of recipient to whom the data might be
disclosed;
(e)
proposed transfers of data to third countries; and
(f) a
general description allowing a preliminary assessment to be made of
the appropriateness of the measures taken pursuant to article 26 to
ensure security of processing:
Provided that the
controller shall notify the Commissioner of any changes affecting
the information referred to under this sub article and the Minister
may prescribe any matter related to the form of such notification.
(4) The
Commissioner may allow the simplification of or the exemption from
the notification obligations provided for under this Part of this
Act only in respect of categories of processing operations -
(i) which are
unlikely, due account being taken of the data being processed, to
prejudice the rights and freedoms of data subjects, and
(ii) in respect of
which the Commissioner specifies the purposes of the processing, the
data or categories of data being processed, the category or
categories of data subjects affected by such processing, the
recipients or categories of recipients to whom the data is to be
disclosed and the length of time for which the data is to be stored.
There is an annual
notification fee – details are on the website
|