Section 32: Data matching
repealed (no longer in force). juris shows the text as it was consolidated; it does not confirm that this is the law in force today. The records juris holds show this law as repealed.
32. Data matching
(1) No data controller shall carry out a data matching procedure unless—
(a) (i) the data subject whose personal data is the subject of that
procedure has given his consent to the procedure being carried out;
(ii) the Commissioner has consented to the procedure being
carried out; and
(iii) the procedure is carried out in accordance with such conditions as the Commissioner may impose; or
(b) it is required or permitted under any other enactment.
(2) Subject to subsection (3), a data controller shall not take any adverse
action against any data subject as a consequence of the carrying out of a
data matching procedure—
(a) unless the data controller has served a notice in writing on the
data subject—
(i) specifying the adverse action it proposes to take and the
reasons therefor;
(ii) stating that the data subject has 7 days after the receipt of
the notice to show cause why the adverse action should
not be taken; and
(b) until the expiry of the 7 days specified in paragraph (a).
D3 – 19 [Issue 3]
Data Protection Act
(3) Subsection (2) shall not preclude a data controller from taking any
adverse action against any data subject if compliance with the requirements
of that subsection shall prejudice any investigation into the commission of
any offence which has been, is being or is likely to be committed.
(S. 32 came into operation on 16 February 2009.)
PART V – THE DATA PROTECTION REGISTER