Tonga Privacy Act 2025
Part III: obligations of data controllers and data processors – Tonga Privacy Act 2025

Tonga Privacy Act 2025 s34: s.34 Keep personal information no longer than necessary, then return, destroy or de-identify it

Personal information may not be kept (by the controller or its processors) longer than needed for its purpose; when no longer needed it must within a reasonable time be returned, destroyed, permanently de-identified or made permanently inaccessible, including all copies. Historical, archival, statistical or research collection and retention required or authorised by law are excepted, and regulations may set longer periods.

Maintained by Gerard Blokdyk

Other controls in Part III: obligations of data controllers and data processors – Tonga Privacy Act 2025

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.