Data Protection » History » Version 8

Version 7 (Steve Welburn, 2012-11-20 09:57 AM) → Version 8/23 (Steve Welburn, 2012-11-20 10:11 AM)

h2. Data Protection

Data protection protects the rights of individuals over their personal information, particularly data should only be used for the purposes for which it has been gathered and should be held appropriately securely.

The core of the Data Protection Act is a set of data protection principles. These state that personal principles:

bq. 1. Personal
data shall be processed fairly and lawfully and and, in particular, shall not be processed unless unless:
a) At least one of
the subject gave their consent except under "specific conditions":http://www.legislation.gov.uk/ukpga/1998/29/schedule/2 (for conditions in Schedule 2 is met, and
b) In the case of
sensitive personal data, there are "further restrictions":http://www.legislation.gov.uk/ukpga/1998/29/schedule/3). In addition, personal at least one of the conditions in Schedule 3 is also met.
2. Personal
data should be:
*
shall be obtained only for one or more specified and lawful purposes, and should shall not be used for anything else; further processed in any manner incompatible with that purpose or those purposes.
* 3. Personal data shall be adequate, relevant and not excessive in relation to the purpose or purposes (i.e. only the for which they are processed.
4. Personal
data that is required);
*
shall be accurate and, where necessary, kept up to date; date.
* 5. Personal data processed for any purpose or purposes shall not be kept no for longer than is necessary for the purposes; that purpose or those purposes.
* 6. Personal data shall be processed in accordance with the rights of the data subjects under the Act; this Act.
* protected from:
**
7. Appropriate technical and organisational measures shall be taken against unauthorised or unlawful processing
**
of personal data and loss, destruction; against accidental loss or destruction of, or damage to, personal data.
* 8. Personal data shall not be transferred to a country or territory outside the European Economic Area without similar unless that country or territory ensures an adequate level of protection being provided.

Further information:
* QMUL Academic Registry and Council Secretariat (ARCS) information on "data protection":http://www.arcs.qmul.ac.uk/information_governance/dp/data_protection.html
* JISC "Data Protection Code of Practice for HE and FE":http://www.jisc.ac.uk/publications/generalpublications/2001/pub_dpacop_0101.aspx
* Canterbury Christchurch University document on "Data Protection in Research":http://www.canterbury.ac.uk/Research/Documents/DataProtection.pdf
* "EU Data Protection Directive":http://ec.europa.eu/justice/data-protection/index_en.htm

The Act:
* "Data Protection Act 1998":http://www.legislation.gov.uk/ukpga/1998/29/contents