Country-specific guidance Current
PDPA obligations when collecting client personal data
Three separate obligations, not one general consent requirement.
Collecting a client's personal data as part of onboarding triggers three distinct obligations under the Personal Data Protection Act, not a single general consent requirement. This guide sets out what each one requires. It is general information, not legal or compliance advice.
Action plan
1 Obtain consent before collecting, using, or disclosing personal data The Consent Obligation sits before collection, not as a formality added afterwards.
The PDPA's Consent Obligation requires an organisation to obtain the individual's consent before collecting, using, or disclosing their personal data for a purpose, unless an exception under the Act applies. Build consent into the collection step itself rather than treating it as paperwork to complete afterwards.
- Obtain consent before collection, use, or disclosure, not afterwards
- Check whether a specific PDPA exception genuinely applies before treating consent as unnecessary
- Keep a record that consent was obtained
Done when: Consent was obtained before the client's personal data was collected, used, or disclosed
PDPC: data protection obligations2 Notify the client of the purpose at or before collection This is a separate obligation to obtaining consent, and it has its own timing requirement.
The PDPA's Notification Obligation requires an organisation to notify the individual of the purpose(s) for which it intends to collect, use, or disclose their personal data, on or before that collection, use, or disclosure takes place. Tell the client what you're collecting their information for at the point you ask for it.
- State the purpose of collection at or before the point of collection
- Cover use and disclosure purposes, not only collection
- Don't rely on a general privacy policy alone to satisfy a specific notification
Done when: The client was notified of the purpose of collection at or before it took place
PDPC: data protection obligations3 Limit use of the data to purposes that were notified or a reasonable person would expect Collecting data for one purpose doesn't authorise using it for another.
The PDPA's Purpose Limitation Obligation restricts an organisation to collecting, using, or disclosing personal data only for purposes a reasonable person would consider appropriate in the circumstances, and, where applicable, that have actually been notified to the individual. Using client data collected for one engagement for an unrelated purpose falls outside this limit.
- Use client data only for the purposes notified or a reasonable person would expect
- Treat a new, unrelated use as requiring fresh notification and consent
- Review whether existing uses of held data still match what was originally notified
Done when: Client data in use matches the purposes that were notified, not a broader or unrelated use
See requesting identity documents from an individual client