5
Not kept longer than necessary.
In full: ‘Personal data processed for any purpose or purposes shall not be kept for longer than
is necessary for that purpose or those purposes.’
The guidelines state: ‘To comply with this Principle, data controllers will need to review
their personal data regularly and to delete the information which is no longer required for
their purposes.’
It might be in a company’s interests to ‘clean data’ so that records that are not relevant
are archived or deleted. However, there is the possibility that the customer may still buy
again, in which case the information would be useful. For example, a car manufacturer
could justifiably hold data for several years.
If a relationship between the organisation and the data subject ends, then data should
be deleted. This will be clear in some instances; for example, when an employee leaves a
company their personal data should be deleted.
Do'stlaringiz bilan baham: |