Final Principles of Personal Data Protection 6. The Participants recognise the need to protect and prevent misuse of an individual’s personal data and will endeavour to take into account and implement in their domestic laws and regulations the following Personal Data Protection Principles (the “Principles”) in accordance with this Framework: Consent, Notification and Purpose (a) (b) An organisation should not collect, use or disclose personal data about an individual unless: (i) the individual has been notified of and given consent to the purpose(s) of the collection, use or disclosure of his/her personal data; or (ii) the collection, use or disclosure without notification or consent is authorised or required under domestic laws and regulations. An organisation may collect, use or disclose personal data about an individual only for purposes that a reasonable person would consider appropriate in the circumstances. Accuracy of Personal Data (c) The personal data should be accurate and complete to the extent necessary for the purpose(s) for which the personal data is to be used or disclosed. Security Safeguards (d) The personal data should be appropriately protected against loss and unauthorised access, collection, use, disclosure, copying, modification, destruction or similar risks. Access and Correction (e) Upon request by an individual, an organisation should: (i) provide the individual access to his/her personal data which is in the possession or under the control of the organisation within a reasonable period of time; and (ii) correct an error or omission in his personal data, unless domestic laws and regulations require or authorise the organisation not to provide access or correct the personal data in the particular circumstances. Page 3 of 6

Select target paragraph3