Information utility duties: protect user consent and data, and restrict outsourcing and secondary use under regulations. Regulation 30 requires an information utility to provide services only with user consent, protect user rights, preserve records, adopt secure information flows, secure data processing systems against unauthorised access or alteration, and transfer a user's stored information to another information utility on the user's request. It prohibits outsourcing core services, using stored information for purposes other than providing regulated services without Board approval, and seeking user data beyond what is necessary to provide those services.
Cases where this provision is explicitly mentioned in the judgment/order text; may not be exhaustive. To view the complete list of cases mentioning this section, Click here.
Provisions expressly mentioned in the judgment/order text.
Information utility duties: protect user consent and data, and restrict outsourcing and secondary use under regulations.
Regulation 30 requires an information utility to provide services only with user consent, protect user rights, preserve records, adopt secure information flows, secure data processing systems against unauthorised access or alteration, and transfer a user's stored information to another information utility on the user's request. It prohibits outsourcing core services, using stored information for purposes other than providing regulated services without Board approval, and seeking user data beyond what is necessary to provide those services.
Full Summary is available for active users!
Note: It is a system-generated summary and is for quick reference only.