Unbenanntes Dokument

Change of purpose


Intro: What is meant by a change of purpose, what function does it have and what must be taken into account when implementing it?

To-Dos: What is the specific procedure for implementing the change of purpose and the associated obligations?

Statements: What have the data protection supervisory authorities published on the subject of change of purpose?






Implement change of purpose in compliance with the law





What is meant by a change of purpose, what function does it have and what must be taken into account when implementing it?

The purpose or purposes of data processing must always be defined before data processing begins (principle of purpose limitation). This is intended to ensure that all data processing is subject to justification and that the necessity of certain data processing has a clear reference point - i.e. the respective purpose.

Nevertheless, the GDPR recognises that there are situations in which a change of purpose is legitimate, i.e. the data may be used for another purpose. This is the case if the following criteria are met:

  • close content-related connection between the old and the newly added purpose
  • against the background of the data collection context, a change of purpose is not far-fetched from the data subject's perspective
  • criticality of the data (e.g. no processing of data in accordance with Art. 9 or 10 GDPR)
  • no negative consequences for the person concerned
  • existence of protective measures such as encryption or pseudonymisation of the data.
An example of such a legitimate change of purpose could be that data (e.g. location data), which must be collected anyway in order to provide a service requested by the person, is also used to make it easier for the person to find this service.

In some cases, however, a change of purpose could contradict the so-called privacy by default principle, according to which the person and not the company should authorise the extended use of the data.

If a change of purpose is to be made, the person concerned must be informed in advance.



What is the specific procedure for implementing the change of purpose and the associated obligations?

1

Carrying out a so-called compatibility check based on the above criteria


2

Informing the data subject about the impending change of purpose


3

Adaptation of the processing overview and data protection information




What have the data protection supervisory authorities published on the subject of change of purpose?


>> Find out which other data protection obligations have to be considered with respect to European data protection law.



Unbenanntes Dokument


Appoint a cost-effective data protection officer now

Do you need support with the implementation of data protection requirements? about our data protection packages.
Unbenanntes Dokument

We are

familiar with the characteristics of small and large companies

experienced in communicating with data protection authorities

active in data protection for over 10 years.