Data Protection Act 1998 Flashcards
LO2 (6 cards)
What is the Data Protection Act 1998?
Aims to ensure data is used as it should be.
Only shared with authorised individuals who need to know.
Kept safe and secure.
What are the 8 principles of DPA 1998?
Fair and Lawful Processing= personal data must be processed fairly, lawfully and transparently.
Purpose Limitation= data must be obtained only for specified and lawful purposes, it must not be processed in any manner incompatible with those purposes.
Data Minimisation= personal data should be adequate, relevant and not excessive for the purposes for which it is processed.
Accuracy= personal data must be accurate and kept up to date.
Storage Limitation= data should not be kept for longer than necessary for its stated purpose.
Rights of Individuals= data should be processed in accordance with the rights of data subjects and they have a right to access their data.
Security= appropriate technical and organisational measures must be taken to protect personal data against unauthorised or unlawful processing and against accidental loss, destruction, or damage.
International Transfers= personal data shouldn’t be transferred outside of the European Economic Area (EEA) unless there is adequate protection for the rights of the data subject.
What is the General Data Protection Regulation (GDPR)?
The law that tells you what you must do when you handle personal data.
All organisations that collect or use personal data must comply with it.
Must: process the least possible amount of personal data, report any security breaches, only keep it for as long as you need to.
What are the 7 principles of GDPR?
Lawfulness, fairness, transparency.
Purpose Limitation.
Data Minimisation.
Accuracy.
Storage Limitation.
Integrity, confidentiality
Accountability
What is the Information Commissioner’s Office (ICO)?
The UK’s regulator for data protection.
Ensures organisations comply with data laws and protects individual’s privacy rights.
What are the main roles of ICO?
- Enforcing data protection laws.
- Issuing guidance.
- Investigating complaints.
- Imposing fines.
5.Raising public awareness.