(1)
Aperson may process the personal data of a Data Principal only in accordance with the provisions of this Act and for a lawful purpose,—
(a) for which the Data Principal has given her consent; or
(b) for certain legitimate uses.
(2)
For the purposes of this section, the expression “lawful purpose” means any purpose which is not expressly forbidden by law.