Updated on 2025-05-22 GMT+08:00

SEC08-04 Data Collection Compliance

It refers to that the data controller shall comply with relevant laws, regulations, and privacy protection guidelines when collecting personal data, and ensure that data collection activities comply with laws and regulations and respect data subjects' rights.

  • Risk level

    High

  • Key strategies
    • Personal data collected only after data subjects' authorization is obtained
    • Sensitive personal data collection must obtain explicit consent from data subjects.
    • The collection scope, purposes, and processing method of using personal data shall not exceed those specified in the privacy statement and must comply with the minimization principle.
    • Provide data subjects with a way to withdraw or change their consent after obtaining their consent.