Help Center/ Well-Architected Framework/ Well-Architected Framework and Practices/ Security Pillar/ Data Security and Privacy Protection/ SEC08 Data Privacy Protection/ SEC08-04 Data Collection Compliance
Updated on 2025-05-22 GMT+08:00
SEC08-04 Data Collection Compliance
It refers to that the data controller shall comply with relevant laws, regulations, and privacy protection guidelines when collecting personal data, and ensure that data collection activities comply with laws and regulations and respect data subjects' rights.
- Risk level
High
- Key strategies
- Personal data collected only after data subjects' authorization is obtained
- Sensitive personal data collection must obtain explicit consent from data subjects.
- The collection scope, purposes, and processing method of using personal data shall not exceed those specified in the privacy statement and must comply with the minimization principle.
- Provide data subjects with a way to withdraw or change their consent after obtaining their consent.
Parent topic: SEC08 Data Privacy Protection
What is your overall rating for this page?
0
1
2
3
4
5
6
7
8
9
10
Very dissatisfiedVery satisfied
Thank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
The system is busy. Please try again later.
For any further questions, feel free to contact us through the chatbot.
Chatbot