customer information shall be obtained only for the purpose of delivering and improving the Services and will not be processed in any manner incompatible with this purpose;
customer information shall be adequate, relevant and not excessive in relation to the abovementioned purpose for which it is collated and/or processed;
customer information shall be accurate, and where necessary, kept up to date and reasonable steps shall be taken to ensure that information which is inaccurate and/or incomplete, having regard to the purpose for which it was collected, is erased or rectified;
customer information shall be kept in a format which permits identification for no longer than is necessary for the purpose for which the information was collected or processed.
Customer information may only be processed if:
the customer has unambiguously given his consent; or
processing is necessary for:
the performance of a contract to which the customer is a party; or
in order to take steps at the request of the customer prior to entering into a contract; or
for compliance with a legal obligation to which FCPSA is subject; or
the performance of a task carried out in the public interest or in the exercise of official authority vested in the recipient; or
for purposes of the legitimate interest pursued by FCPSA, except where such interest is overridden by the interest for fundamental rights as reflected in the constitution.
Access to Customer Information
FCPSA shall ensure that:
access to, or disclosure of customer information will not be authorized without the documented commitment of the intended recipient so as to maintain confidentiality and the rightful use of such information;
access to customer information by FCPSA personnel, contract workers, consultants, service providers or suppliers will be restricted to the level of access needed to effectively perform delegated or contracted duties and/or the level of service needed to render a reliable and effective service to FCPSA customers.
FCPSA shall ensure that appropriate technical and organizational measures shall be taken against the unauthorized access, processing or disclosure of customer information