Skip to main content

Specify the purpose of data collection


The system must specify the purpose of personal data collection (OECD.9, ISACA.G31.3.), and it must do so before requesting the users consent for the collection.


Applications usually request or collect personal data from their users. Such collection must be properly justified according to the legal requirements of each nation. These reasons must be accessible for the user in a clear manner, using easily understandable language and before requesting their consent for the collection and processing of data.

Supported In

This requirement is verified in following services




free trial

Search for vulnerabilities in your apps for free with our automated security testing! Start your 21-day free trial and discover the benefits of our Continuous Hacking Machine Plan. If you prefer a full service that includes the expertise of our ethical hackers, don't hesitate to contact us for our Continuous Hacking Squad Plan.