logo

189 Specify the purpose of data collection


Summary

The system must specify the purpose of personal data collection (OECD.9, ISACA.G31.3.), and it must do so before requesting the users consent for the collection.


Description

Applications usually request or collect personal data from their users. Such collection must be properly justified according to the legal requirements of each nation. These reasons must be accessible for the user in a clear manner, using easily understandable language and before requesting their consent for the collection and processing of data.


Supported In

Advanced: True


References


Weaknesses


Last updated

2024/01/18