You are on page 1of 9

Data Protection

Act

Data Protection Act 1998

Piece of legislation

The DPA is a law designed to protect your


personal data that is stored on computers.

Affects our lives almost everyday

Terminology
Personal
data

Data
Processor/
User

Data
subject
Data
Controller

Informant
Commissioner

Personal
data

This is the person


that the data is
being collected
about

Includes facts and


opinions that are
held about a living
individual

Data
subject

Data
Processor/
User

Someone who
accesses and
uses the data as
a part of their job

Data
Controller

This person is responsible


for enforcing the DPA
across the UK.

This may be the person in


charge of the organisation
they will be the person that
gains permission to collect
and store the data

Informant
Commissioner

Principle

Meaning

Personal data
should be obtained
and processed fairly
and lawfully

Data cannot be collected without your


permission and you should be told which
data is being collected and why.

Personal data can


only be held for
specified purpose

The data controller must state why they


want to collect and store information. They
must not use the data they have collected
for other purposes.

Personal data
should be adequate
and relevant

Organisations must collect only the data


they need and no more.

Personal data
Companies should do their best to make
should be kept up- sure that the data they collect is correct and
to-date and accurate
updated when required

Principle

Meaning

Personal data
should not be kept
for longer than
necessary

Organisations should only keep data for a


reasonable length of time.

Data must be
processed in
accordance with the
rights of the data
subject

People have the right to access the


information that is held on them. If the
information being held on them is incorrect
then it should be changed.

Authorised access
only

This mean information should be kept safe


and only authorised people can access it. It
should be kept safe from hackers.

Personal data
If an organisation wishes to share data they
should not be
must have similar laws to our DPA.
transferred outside
counteries in the EU

Sensitive Data
Racial or ethnic origin
Membership of a trade union
Criminal convictions
Political opinions
Religious beliefs

You might also like