Collecting personal data is not the same as being able to use it

Articles24 August 2026
The fact that a company obtains data lawfully does not necessarily mean that it can use it for any subsequent purpose. This is one of the most important – and still poorly understood – concepts in the field of personal data protection.

Data protection, however, does not work quite like that. The question is not simply whether we were able to obtain the data, but why we obtained it and what we now intend to use it for.


Act 172-13 is clear regarding the purpose of data processing. Data must be adequate, relevant and not excessive in relation to the specified, explicit and legitimate purposes for which it was collected. This allows us to distinguish between two issues that many organisations tend to treat as one: the legitimacy of having collected the data and the legitimacy of subsequently using it for a different purpose. These are related issues, but they are not equivalent. A company may ask a customer for their telephone number to manage a service, but this does not mean that it can subsequently use it for any marketing campaign, share it with a third party or store it in a database for a purpose entirely different from the original one.


This is particularly relevant because much of the discussion on privacy centres on the accuracy and security of information – that is, whether the data is correct and whether it is properly safeguarded. However, less attention is often paid to a risk that is more difficult to identify. Data may be perfectly accurate and adequately protected, yet still be used in a way that does not correspond to the purpose for which it was collected. Examples of this are commonplace. A company collects contact details to manage a contractual relationship and then uses them for marketing campaigns. An employer gathers information about its employees for administrative purposes and ends up feeding it into automated assessment or monitoring systems. A business obtains information from its customers to provide a service and subsequently shares it with a third party to develop a new product. A company collects information during a recruitment process and ends up using it to create candidate profiles. In all these cases, the data may have been collected entirely lawfully, yet the new use may not be compatible with the original purpose.


It is also worth noting another common mistake here, which is the assumption that a general consent clause is sufficient for any subsequent use. Law 172-13 requires that, where processing requires consent, the data subject must be informed in advance of the purpose for which their data will be used and of who the recipients may be. Therefore, a generic authorisation does not necessarily permit the use of the data for any purpose that may arise in the future. Transparency regarding the purpose is part of the legitimacy of the processing and should not be viewed as a mere formality to be fulfilled only once.


With artificial intelligence, the problem takes on a whole new dimension. Many companies are taking information they already hold to feed AI systems, train models, automate processes, generate profiles or improve products, and the question they should ask themselves before uploading that data to a tool – and which they almost never do – is whether the mere fact of already holding the data entitles them to use it for that new purpose. The answer should not be taken for granted. Before reusing personal data for a new purpose, the company would need to be able to explain why it originally collected the data, what the new purpose is, what the relationship is between the two, what was communicated to the data subject at the time, whether this new use requires additional consent, who will have access to the data, whether it will be shared with suppliers or third parties, whether it will leave Dominican territory, how long it will be retained for this new purpose, and what additional risks the new processing entails.


And it is at this point that data protection ceases to be a matter of forms and privacy policies published on a website, and becomes a matter of governance. A truly well-prepared company should be able to answer, without having to investigate, what data it holds, where it comes from, why it was collected, what it is currently being used for, who has access to it, which suppliers receive it, and what new uses are being considered. If it cannot answer these questions, the problem is not that it lacks a well-drafted privacy policy; it is that it lacks governance over its own information.


With the entry into force of the new Dominican Penal Code, this analysis takes on a dimension it did not previously have. Article 198 of Law 74-25 penalises certain acts involving the collection and unauthorised use of personal data, with criminal consequences for anyone who commits such acts with intent, and Article 199 goes further by establishing that legal entities may be held criminally liable under the conditions set out in the Act itself. That changes the conversation. It is no longer simply a matter of assessing whether a company might face a claim, but one of risk management and corporate responsibility in the most literal sense. A company lacking such control over its own data may be bearing risks of which it is not even aware.


Therefore, before reusing personal data for a new initiative, a marketing campaign, a technological tool or an artificial intelligence model, the question every company should ask itself is not whether it holds that data. It is whether it has a legitimate basis for using it in that way and for that specific purpose. The difference between the two questions may seem small, but legally it can be enormous. In an environment where data is constantly reused to create products, automate decisions and generate new lines of business, an organisation’s ability to govern the purposes for which its data is used is becoming a strategic compliance issue, not merely a privacy exercise. And perhaps the question that really matters is no longer how much a company knows about its customers, but whether it knows what it is authorised to use that knowledge for.

La imagen muestra una serie de cortinas rojas que crean un efecto dramático de color.
  • Artificial Intelligence

Related professionals

LATEST FROM #ECIJA