Often Asked Queries About Information Protection

Why is it important for your organisation to comply with the Data protection Act?

The Information Protection Act 1998 (“DPA”), lays down eight data protection principles that any organisation processing information of individuals will have to comply with.

What does the DPA cover?

The DPA came into force on 1 March 2000. The DPA implemented the European Union (“EU”) Directive on data protection into UK law introducing radical adjustments to the way in which personal information with regards to identifiable living folks can be made use of. The constant want for companies to approach personal data signifies that the DPA impacts upon most organisations, irrespective of size. Moreover, the public’s expanding awareness of their right to privacy means that information protection will stay an crucial concern.

The DPA tends to make a distinction amongst private data and individual sensitive information. Private information includes personal information relating to staff, buyers, organization contacts and suppliers. Sensitive data covers an individual’s ethnic origin, healthcare situations, sexual orientation and eligibility to operate in the UK . Rechtsanwalt Hattingen set out the standards which an organisation should meet when processing private data. These principles apply to the processing of all individual information, whether or not those information are processed automatically or stored in structured manual files.

What is data?

Information suggests details which is processed by laptop or computer or other automatic equipment, which includes word processors, databases and spreadsheet files, or details which is recorded on paper with the intention of being processed later by pc or info which is recorded as component of a manual filing system, where the files are structured according to the names of people or other characteristics, such as payroll quantity, and where the files have enough internal structure so that particular information about a unique person can be found quickly.

What are the eight information protection principles?

The eight information protection principles are as follows:

Personal data must be processed pretty and lawfully

Individual data should be obtained only for specified and lawful purposes and ought to not be processed further in any manner incompatible with these purposes

Individual data need to be adequate, relevant and not excessive in relation to the purposes for which they had been collected

Individual information will have to be accurate and, where essential, kept up to date

Private data will have to not be kept longer than is important for the purposes for which they had been collected

Private data should be processed in accordance with the rights of data subjects

Personal information need to be kept safe against unauthorised or unlawful
processing and against accidental loss, destruction or harm

Individual data ought to not be transferred to countries outdoors the European

Economic Area unless the country of location delivers an adequate level of data protection for these data.

What information comprises individual information?

Private data relates to data of living men and women who can be identified from these information, or from those information and other facts which is in the possession of the data controller or which is probably to come into its possession for example, names, addresses and residence phone numbers of staff.

What data comprises sensitive information?

Private Sensitive information (“sensitive information “) consist of information relating to a information subject’s (individuals):

racial or ethnic origin

political opinions

religious beliefs or other comparable beliefs

trade union membership

physical or mental wellness or condition

sexual orientation

commission or alleged commission of any offences convictions or criminal proceedings involving the data topic.

convictions or criminal proceedings involving the data subject.

What is the which means of processing under the DPA?

The definition of ‘processing’ is really broad. It covers any operation carried out on the data and involves, acquiring or recording data, the retrieval, consultation or use of information, the disclosure or otherwise creating readily available of data.

Who is a information controller?

A ‘data controller’ is any individual who (alone or jointly with other individuals) decides the purposes for which, and the manner in which, the personal information are processed. The information controller will thus be the legal entity which exercises ultimate manage more than the private information. Individual managers or staff are not information controllers.

The data controller is accountable for:

Private data about identifiable living individuals

Deciding how and why individual data are processed

Information and facts handling – complying with the eight information protection principles

Acquiring “data subjects” consent for processing sensitive information

Current procedures for handling sensitive or individual information

Safety measures to safeguard personal data

Notification

Who is a data processor?

A ‘data processor’ is a person or organisation who processes the information on behalf of the data controller, but who is not an employee of the information controller.

Who is a information subject?

A ‘data subject’ is any living person who is the topic of personal data. There are no age restrictions on who qualifies as a information subject, but the definition does not extend to men and women who are deceased.

Are we expected to notify? What does notification imply?

An organisation need to not procedure any personal information unless it has initial notified the Data Commissioner of particular particulars, such as:

the organisation’s name and address

the purposes for which the information are to be processed

any proposed recipients of the information

countries outdoors the European Financial Area to which the data may well be disclosed.