18 – Notification to data subject when collecting personal information
- If personal information is collected, the responsible party must take reasonably practicable steps to ensure that the data subject is aware of –
- The information being collected and where the information is not collected from the data subject, the source from which it is collected;
- The name and address of the responsible party;
- The purpose for which the information is being collected;
- Whether or not the supply of the information by that data subject is voluntary or mandatory;
- The consequences of failure to provide the information;
- Any particular law authorizing or requiring the collection of the information;
- The fact that, where applicable, the responsible party intends to transfer the information to a third country or international organization and the level of protection afforded to the information by that third country or international organization;
- Any further information such as the –
- Recipient or category of recipients of the information;
- Nature or category of the information;
- Existence of the right of access to and the right to rectify the information collected;
- Existence of the right to object to the processing of personal information as referred to in section 11(3); and
- Right to lodge a complaint to the Information Regulator and the contact details of the Information Regulator,
Which is necessary, having regard to the specific circumstances in which the information is or is not to be processed, to enable processing in respect of the data subject to be reasonable.
- The steps referred to in subsection (1) must be taken –
- If the personal information is collected directly from the data subject, before the information is collected, unless the data subject is already aware of the information referred to in that subsection; or
- In any other case, before the information is collected or as soon as reasonably practicable after it has been collected.
- A responsible party that has previously taken the steps referred to in subsection (1) complies with subsection (1) in relation to the subsequent collection from the data subject of the same information or information of the same kind if the purpose of collection of the information remains the same.
- It is not necessary for a responsible party to comply with subsection (1) if –
- The data subject or a competent person where the data subject is a child has provided consent for the non-compliance;
- Non-compliance would not prejudice the legitimate interests of the data subject as set out in terms of this Act;
- Non-compliance is necessary;
- To avoid prejudice to the maintenance of the law by any public body, including the prevention, detection, investigation, prosecution and punishment of offenses;
- To comply with an obligation imposed by law or to enforce legislation concerning the collection of revenue as defined in section 1 of the South African Revenue Service Act, 1997 (Act 34 of 1997);
- For the conduct of proceedings in any court or tribunal that have been commenced or are reasonably contemplated; or
- In the interests of national security;
- Compliance would prejudice a lawful purpose of the collection;
- Compliance is not reasonably practicable in the circumstances of the particular case; or
- The information will –
- Not be used in a form in which the data subject may be identified; or
- Be used for historical, statistical or research purposes