Regulation of Personal Information Daniel Pettitt, Leon Sewell and Matthew Pallot.

Slides:



Advertisements
Similar presentations
Confidentiality and Legislation The boring little things that you REALLY need to know about! …
Advertisements

Legislation & ICT By Savannah Inkster. By Savannah Computer Laws 1.Data Protection ActData Protection Act 2.Computer Misuse ActComputer Misuse Act 3.Copyright,
Legislation in ICT.
Introduction to the APPs and the OAIC’s regulatory approach Presented by: Este Darin-Cooper Director, Regulation and Strategy May 2015.
Role of the Information Commissioner’s Office 'Promoting public access to official information and protecting your personal information' Christine Johnson.
University of Sunderland Professionalism and Personal Skills Unit 11 Professionalism and Personal Skills Computer Legislation.
Legislation in ICT. Data Protection Act (1998) What is the Data Protection Act (1998) and why was it created? What are the eight principles of the Data.
Data Protection Act.
Data Protection Act Description The Data Protection Act controls how your personal information can be used and protects from the misuse of your.
Information Commissioner’s Office: data protection Judith Jones Senior Policy Officer Strategic Liaison – public security 16 November 2011.
Data Protection Paul Veysey & Bethan Walsh. Introduction Data Protection is about protecting people by responsibly managing their data in ways they expect.
Data Protection Overview
The Data Protection Act
Protecting information rights –­ advancing information policy Privacy law reform for APP entities (organisations)
Data Protection Act. Lesson Objectives To understand the data protection act.
The ICO and the DPA Ken Macdonald Assistant Commissioner Information Commissioner’s Office ScotStat Public Sector Analysts Network 30 th September 2010.
 The Data Protection Act 1998 is an Act of Parliament which defines UK law on the processing of data on identifiable living people and it is the main.
1 OVERVIEW PRESENTATION FREEDOM OF INFORMATION (SCOTLAND) ACT 2002.
Data Protection for Church of Scotland Congregations
1 Freedom of Information (Scotland) Act 2002 A strategic view.
Elma Graham. To understand what data protection is To reflect on how data protection affects you To consider how you would safeguard the data of others.
707 KAR 1:360 Confidentiality of Information. Section 1: Access Rights 1) An LEA shall permit a parent to inspect and review any education records relating.
The Data Protection Act 1998 The Eight Principles.
OCR Nationals Level 3 Unit 3.  To understand how the Data Protection Act 1998 relates to the data you will be collecting, storing and processing  To.
Data Protection Act 171 Computers and privacy There are problems as more computers are used There are problems as more computers are used More and more.
Data Protection Act AS Module Heathcote Ch. 12.
FatMax Licensed under a Creative Commons Attribution-NonCommercial-ShareAlike 2.5 LicenseCreative Commons Attribution-NonCommercial-ShareAlike 2.5.
Data Protection Act & Freedom of Information Simon Mansell Corporate Governance and Information Team.
The Data Protection Act (1998). The Data Protection Act allows you to Check if any organisation keeps information about you on computer or in paper form.
Data Protection Corporate training Data Protection Act 1998 Replaces DPA 1994 EC directive 94/46/EC The Information Commissioner The courts.
Processing personal health data: the regulator’s perspective Ken Macdonald Assistant Commissioner Information Commissioner’s Office.
The Data Protection Act What Data is Held on Individuals? By institutions: –Criminal information, –Educational information; –Medical Information;
BTEC ICT Legal Issues Data Protection Act (1998) Computer Misuse Act (1990) Freedom of Information Act (2000)
Data Protection Act (1984, 1998). 2 Data Protection Act There are many organisations which hold personal information about individuals Examples: Loyalty.
Legal issues The Data Protection Act Legal issues What the Act covers The misuse of personal data By organizations and businesses.
The Data Protection Act What the Act covers The misuse of personal data by organisations and businesses.
Introduction Data protection is relevant to every individual, business or organisation today, not just Local Government. As well as protecting privacy,
Data Protection - Rights & Responsibilities Information Commissioner’s Office Orkney Practice Forum 4 th July 2007.
THE DATA PROTECTION ACT Data Protection Act 1998 DPA 1. Reasons2. People3. Principles 4. Exemptions 4 key points you need to learn/understand/revise.
Data Protection Act The Data Protection Act (DPA) is a balance between rights of the DATA SUBJECT and obligations of the DATA CONTROLLER DATA CONTROLLER.
An Introduction to the Privacy Act Privacy Act 1993 Promotes and protects individual privacy Is concerned with the privacy of information about people.
Data Protection Act (1998).
Computing, Ethics & The Law. The Law Copyright, Designs and Patents Act (1988) Computer Misuse Act (1990) Data Protection Act (1998) (8 Main Principles)
DATA PROTECTION ACT (DPA). WHAT IS THE DATA PROTECTION ACT?  The Data Protection Act The Data Protection Act (DPA) gives individuals the right.
What is the Data Protection Act (DPA)? 1998 The Data Protection Act 1998 seeks to strike a balance between the rights of individuals and the sometimes.
GCSE ICT Data and you: The Data Protection Act. Loyalty cards Many companies use loyalty cards to encourage consumers to use their shops and services.
DATA PROTECTION AND RUNNING A COMPLIANT PUB WATCH SCHEME Nigel Connor Head of Legal –JD Wetherspoon PLC.
© University of Reading Lee Shailer 06 June 2016 Data Protection the basics.
Workshop Understanding your responsibilities under the Data Protection Act 1998 and the Freedom of Information Act 2000 Adele Rhodes Girling.
Sharing Personal Data ‘What you need to know’ Corporate Information Governance Team Strategic Intelligence.
Freedom of Information Act ‘What you need to know’ Corporate Information Governance Team Strategic Intelligence.
Data Protection and Freedom of Information. Objectives Describe the main points of the Data Protection Act 1998 and Freedom of Information Act 2000 Illustrate.
Data Protection Laws in the European Union John Armstrong CMS Cameron McKenna.
The Data Protection Act 1998
The Data Protection Act 1998
Trevor Ellis Trainee Programmer (1981 – 28 years ago)
Legislation in ICT.
Data Protection Act.
APP entities (organisations)
The Data Protection Act 1998
Data Protection Legislation
EU Directive 95/46/EC (Paragraph 2) “Whereas data-processing systems are designed to serve man; whereas they must Respect their fundamental rights.
Data Protection & Freedom of Information- An Introduction
G.D.P.R General Data Protection Regulations
Data Protection principles
Identify the laws and guidelines that affect day-to-day use of IT.
General Data Protection Regulations 2018
What is the Data Protection Act (DPA)? 1998
Legislation in ICT.
Data Protection.
Presentation transcript:

Regulation of Personal Information Daniel Pettitt, Leon Sewell and Matthew Pallot

What is Regulation of Personal Information? Government and companies started using computers to store information such as names, addresses and telephone numbers. This made it easier to access and so easier for the wrong people to get hold of personal data. Parliament passed laws to protect this information, including the Data Protection Act and the Freedom of Information Act.

Who is Affected? The laws cover anyone who has personal information stored about them. They are referred to as Data Subject. Any person or company that compiles information about people is a Data Controller. The person/people in charge of enforcing the laws is the Information Commisioner.

Data Protection Act The Data Protection Act 1998 (DPA) is a United Kingdom Act of Parliament which defines UK law on the processing of data on identifiable living people. It is the main piece of legislation that governs the protection of personal data in the UK. It was introduced to bring UK law into line with the European Directive of 1995 which required Member States to protect people's fundamental rights and freedoms and in particular their right to privacy with respect to the processing of personal data. In practice it provides a way for individuals to control information about themselves. Most of the Act does not apply to domestic use, for example keeping a personal address book. Anyone holding personal data for other purposes is legally obliged to comply with this Act, subject to some exemptions.

Personal data Data may only be used for the specific purposes for which it was collected. Data must not be disclosed to other parties without the consent of the individual whom it is about, unless there is legislation or other overriding legitimate reason. Individuals have a right of access to the information held about them. Personal information may be kept for no longer than is necessary and must be kept up to date.

Data protection principles The Data Protection Act creates rights for those who have their data stored, and responsibilities for those who store, process or collect personal data. The person who has their data processed has the right to: View the data an organization holds on them, for a small fee, known as 'subject access fee. Request that incorrect information be corrected. If the company ignores the request, a court can order the data to be corrected or destroyed, and in some cases compensation can be awarded. Require that data is not used in any way that may potentially cause damage or distress. Require that their data is not used for direct marketing.

Exceptions The Act is structured such that all processing of personal data is covered by the act, while providing a number of exceptions. Notable exceptions are: National security. Any processing for the purpose of safeguarding national security are exempt from all the data protection. Crime and taxation. Data processed for the prevention or detection of crime, the apprehension or prosecution of offenders, or the assessment or collection of taxes are exempt from the first data protection principle. Domestic purposes. Processing by an individual only for the purposes of that individual's personal, family or household affairs is exempt from all the data protection principles.

The Freedom of Information Act gives you the right to obtain information held by public authorities unless there are good reasons to keep it confidential. Freedom of information act

The Freedom of Information Act deals with access to official information and gives individuals or organisations the right to request information from any public authority.

The Basics The Freedom of Information Act deals with access to official information and gives individuals or organisations the right to request information from any public authority. Your legal Obligations All public authorities and companies wholly owned by public authorities have obligations under the Freedom of Information Act. When responding to requests, they have to follow a number of set procedures.

Guidance The ICO publishes detailed guidance notes that provide organisations and individuals with all the information they need to know about the Freedom of Information Act. Decision Notices A Decision Notice outlines the ICO's final assessment, following a complaint, as to whether or not a public authority has complied with the Act. These are catalogued and available online. Enforcement action will be taken against public authorities that repeatedly fail to meet their responsibilities under the act.

Example of Data not being protected This story involves a revenge attack on someone's family, where the home address of the couple was obtained through BT’s systems stmhttp://news.bbc.co.uk/1/hi/england/nottinghamshire/ stm