A data controller shall ensure that personal data is —
(a) kept only for one or more specified and lawful purposes for which the personal data is to be processed;
(b) not used or disclosed in any manner incompatible with the purposes for which the personal data has been processed;
(c) adequate and relevant for the purpose for which the personal data is to be processed; and
(d) not kept for longer than is necessary for the purpose for which the personal data is to be processed.