Data Protection Legislation

Slides:



Advertisements
Similar presentations
Administrative Systems and the Law What you need to know to produce an oral presentation for Unit 7 When the presentations will take place Resources you.
Advertisements

Introduction to basic principles of Regulation (EC) 45/2001 Sophie Louveaux María Verónica Pérez Asinari.
Data Protection Information Management / Jody McKenzie.
The Data Protection (Jersey) Law 2005.
Data Protection & Freedom of Information The Practical Implications of Data Protection and Freedom of Information Caroline Dominey Data Protection Officer.
Duncan Woodhouse – Assistant Registrar for Information Security, Risk Management and Business Continuity Helen Wollerton – Administrative Officer (Legal.
Data Protection Act Description The Data Protection Act controls how your personal information can be used and protects from the misuse of your.
Data Protection Paul Veysey & Bethan Walsh. Introduction Data Protection is about protecting people by responsibly managing their data in ways they expect.
Data Protection Overview
An overview of the Data Protection Act Legal framework The Data Protection Act 1998 came into force in March 2001, replacing the Data Protection.
The Data Protection Act
Data Protection Act. Lesson Objectives To understand the data protection act.
 The Data Protection Act 1998 is an Act of Parliament which defines UK law on the processing of data on identifiable living people and it is the main.
The Legal Framework Can you work out which slide each bullet point should go on?!
Regulation of Personal Information Daniel Pettitt, Leon Sewell and Matthew Pallot.
Data Protection and You Your Rights & The Law Registration Basics Other Activities Disclaimer: This presentation only provides an introductory info. Please.
Elma Graham. To understand what data protection is To reflect on how data protection affects you To consider how you would safeguard the data of others.
The Data Protection Act 1998 The Eight Principles.
OCR Nationals Level 3 Unit 3.  To understand how the Data Protection Act 1998 relates to the data you will be collecting, storing and processing  To.
Data Protection Act AS Module Heathcote Ch. 12.
FatMax Licensed under a Creative Commons Attribution-NonCommercial-ShareAlike 2.5 LicenseCreative Commons Attribution-NonCommercial-ShareAlike 2.5.
Data Protection Corporate training Data Protection Act 1998 Replaces DPA 1994 EC directive 94/46/EC The Information Commissioner The courts.
What is personal data? Personal data is data about an individual which they consider to be private.
The Data Protection Act - Confidentiality and Associated Problems.
The Data Protection Act What Data is Held on Individuals? By institutions: –Criminal information, –Educational information; –Medical Information;
BTEC ICT Legal Issues Data Protection Act (1998) Computer Misuse Act (1990) Freedom of Information Act (2000)
Data Protection Act (1984, 1998). 2 Data Protection Act There are many organisations which hold personal information about individuals Examples: Loyalty.
Legal issues The Data Protection Act Legal issues What the Act covers The misuse of personal data By organizations and businesses.
The Data Protection Act What the Act covers The misuse of personal data by organisations and businesses.
PROTECTION OF PERSONAL DATA. OECD GUIDELINES: BASIC PRINCIPLES OF NATIONAL APPLICATION Collection Limitation Principle There should be limits to the collection.
Introduction Data protection is relevant to every individual, business or organisation today, not just Local Government. As well as protecting privacy,
Data Protection - Rights & Responsibilities Information Commissioner’s Office Orkney Practice Forum 4 th July 2007.
THE DATA PROTECTION ACT Data Protection Act 1998 DPA 1. Reasons2. People3. Principles 4. Exemptions 4 key points you need to learn/understand/revise.
Data Protection Act The Data Protection Act (DPA) is a balance between rights of the DATA SUBJECT and obligations of the DATA CONTROLLER DATA CONTROLLER.
An Introduction to the Privacy Act Privacy Act 1993 Promotes and protects individual privacy Is concerned with the privacy of information about people.
Data Protection Act (1998).
Legal Implications You need to know about the following:
LEGAL IMPLICATION OF THE USE OF COMPUTER Lower Sixth Computing Lesson Prepared by: T.Fina.
DATA PROTECTION ACT (DPA). WHAT IS THE DATA PROTECTION ACT?  The Data Protection Act The Data Protection Act (DPA) gives individuals the right.
What is the Data Protection Act (DPA)? 1998 The Data Protection Act 1998 seeks to strike a balance between the rights of individuals and the sometimes.
DATA PROTECTION ACT INTRODUCTION The Data Protection Act 1998 came into force on the 1 st March It is more far reaching than its predecessor,
GCSE ICT Data and you: The Data Protection Act. Loyalty cards Many companies use loyalty cards to encourage consumers to use their shops and services.
Data protection—training materials [Name and details of speaker]
Presented by Ms. Teki Akuetteh LLM (IT and Telecom Law) 16/07/2013Data Protection Act, 2012: A call for Action1.
Protection of Personal Information Act An Analysis on the impact.
Data protection act. During the second half of the 20th century, businesses, organisations and the government began using computers to store information.
General Data Protection Regulation (EU 2016/679)
The Data Protection Act 1998
The Data Protection Act 1998
Learning Intention Legislations impact on security of information
Making the Connection ISO Master Class An Overview.
Data Protection GCSE ICT Mrs N Steventon-2005.
Lesson 3 Protecting ICT systems Data Protection Act 1998.
Trevor Ellis Trainee Programmer (1981 – 28 years ago)
Level 2 Diploma in Customer Service
Handout 2: Data Protection and Copyright
Data Protection Act.
General Data Protection Regulation
Data Protection Act.
The Data Protection Act 1998
Data Protection & Freedom of Information- An Introduction
Data Protection Act.
G.D.P.R General Data Protection Regulations
Data Protection principles
Identify the laws and guidelines that affect day-to-day use of IT.
Mathew Norman, Policy & Public Affairs Officer, RLA Wales
General Data Protection Regulations 2018
What is the Data Protection Act (DPA)? 1998
Identify the laws and guidelines that affect day-to-day use of IT.
Presentation transcript:

Data Protection Legislation

Personal Privacy The right to privacy is a fundamental human right Development of databases has led to storage of lots of personal information without the knowledge or permission of the individual It is often felt that even the use of names and addresses for mail shots is an invasion of privacy The Data Protection Act of 1984 grew out of concern about personal privacy

Data Protection Acts of 1984 and 1998 The act covers ‘personal data’ which are ‘automatically processed’ It works on two levels: To give individuals certain statutory rights To require those who record and use personal data on computers to be open about the use and follow proper procedures

The Data protection Act of 1998 was passed to implement a European Data Protection Directive. This sets a standard for data protection throughout all countries in the EU It came into force in March 2000 Extended to include some manual records Gave further rights to data subjects

The Data Protection Registrar The 1984 Act established the office of Registrar The 1998 Act changed the title to Data Protection Commissioner With effect from 20th January 2001 the title is now Information Commissioner whose duties include: administering a public register of Data Controllers with broad details of the data held; Disseminating information on the Act and how it works Promoting compliance with the Data Protection Principles Considering complaints about breaches of Principles or the Act.; Prosecuting offenders, or serving notices on those who are contravening the principles.

The Principles Personal data must be obtained and processed fairly and lawfully; Personal data must be held for specified (limited) and lawful purposes; Personal data must be adequate, relevant and not excessive; Personal data must be accurate and up-to-date; Personal data must not be kept longer than necessary; Personal data must be processed in accordance with the data subject's rights; Personal data must be kept secure; Personal data must not be transferred to countries without adequate protection;

Useful Definitions from the 1984 Act ‘Personal data’ Information about living, identifiable individuals. Personal data do not have to be particularly sensitive information and can be as little as name and address. ‘automatically processed’ Processed by a computer or other technology such as document image processing systems. ‘data users’ now called ‘data controllers’ under 1998 Act Those who control the contents and use of a collection of personal data. They can be any type of company or organisation, large or small, within the public or private sector. Can also be a sole trader, partnership or an individual. A data user need not necessarily own a computer. ‘data subjects’ The individuals to whom personal data relate

Similar Definitions from the 1998 Act Personal data means data which relates to a living individual who can be identified from those data or from those data and other information which is in the possession of the data controller. A data controller is a person who determines the purposes for which and the manner in which any personal data are, or are to be processed. Every data controller who is processing personal data must notify unless they are exempt. These definitions found at: http://www.dpr.gov.uk/notify/4.html

Data Controller’s Register entry This processing description includes: The purposes for which personal data are being or are to be processed e.g. provision of financial services and advice a description of the data subjects about whom data are or are to be held e.g. customers and clients a description of the data classes e.g. personal details, financial details a list of the recipients of data e.g. financial organisations and advisors information about whether data are transferred outside the European Economic Area (EEA)

Possible Exemptions Some not for profit organisations Processing of personal data for personal, family or household affairs (including recreational purposes). Data controllers who only process personal data for the maintenance of a public register. Data controllers who only process personal data for any one or all of the following purposes for their own business. staff administration advertising, marketing and public relations accounts and records Special categories under which data may be held National security Prevention of crime Collection of tax or duty

Rights of Data subjects An individual is entitled, upon written request, to be supplied with a copy of any personal data held about yourself. The data controller may charge a fee Rights include: Right to compensation for unauthorised disclosure of data Right to compensation for inaccurate data Right of access to data and to apply for rectification or erasure where data are inaccurate Right to compensation for unauthorised access, loss or destruction of data

Implications of the Data Protection Legislation Under the current legislation: use of personal data must be registered the public have a right to see what data is held about them by an organisation However, it is quite legal for an organization to sell a mailing list for the purpose of direct mailing.

European Directive of 24 October 1995 Where data is to be transferred to a third party for the purposes of direct mailing, the subject must be informed and given the opportunity to require that the data be erased. Many organizations collecting personal data include a check box to be ticked if you object to your data being passed on to other organizations. Member states have three years to implement this legislation