Research and the Data Protection and Freedom of Information Acts.


Similar presentations
NIGB Legal requirements for use of personal data in research OnCore UK / NRES Training workshop Ethical Principles relating to consent for use of samples.

Using Information at the University University Secretarys Office
The Legislative Position in Scotland Environmental Information (Scotland) Regulations 2004 SSI 2004 No.520 Professor Colin Reid, School of Law, University.
IMPS Information Management and Policy Services Information Services Directorate A briefing for all University staff November 2004 New Information Legislation.
Data Security Breach Code of Practice. Data Security Concerns Exponential growth in personal data holdings Increased outsourcing 3 rd countries cloud.
Open Access: Data Protection, Storage and Sharing Caroline Dominey.
DATA PROTECTION and Research University Research Ethics Committee – David Cauchi David Cauchi Office of the Commissioner for Data Protection.
Introduction to Information Governance (IG)
Data Protection and Freedom of Information
Freedom of Information Act 2000 and the PCT Audit Procedure Background: The Act was passed in November The Act will be fully in force by January.
Data Protection Information Management / Jody McKenzie.
BIOMETRICS, CCTV & DATA PROTECTION By Drudeisha Madhub Data Protection Commissioner Date:
The Data Protection (Jersey) Law 2005.
Challenges of freedom of information for researchers Susan Graham University Records Manager University of Edinburgh.
Legislation & ICT By Savannah Inkster. By Savannah Computer Laws 1.Data Protection ActData Protection Act 2.Computer Misuse ActComputer Misuse Act 3.Copyright,
BC Freedom of Information and Protection of Privacy Act
Role of the Information Commissioner’s Office 'Promoting public access to official information and protecting your personal information' Christine Johnson.
Duncan Woodhouse – Assistant Registrar for Information Security, Risk Management and Business Continuity Helen Wollerton – Administrative Officer (Legal.
Towards a Freedom of Information Law in Qatar Fahad bin Mohammed Al Attiya Executive Chairman, Qatar National Food Security Programme.
Freedom of Information – a brief guide David Evans.
Data Protection Paul Veysey & Bethan Walsh. Introduction Data Protection is about protecting people by responsibly managing their data in ways they expect.
Data Protection Overview
The Information Commissioner’s Office David Evans.
Public rights of access to information Grisilda Ponniah, Corporate Information Governance Manager Mary Elliott, FOI Officer Legal & Democratic Services.
The Data Protection Act 1998 The Eight Principles.
Data Protection Act obligations and pseudonymisation Dawn Monaghan Group Manager Information Commissioners Office.
OCR Nationals Level 3 Unit 3.  To understand how the Data Protection Act 1998 relates to the data you will be collecting, storing and processing  To.
Data Protection: An enabler? David Freeland, Senior Policy Officer 23 October 2014.
Local Government Reform: Incorporating Planning Functions Ken Macdonald Assistant Commissioner (Scotland & Northern Ireland) Information Commissioner’s.
Data Protection Corporate training Data Protection Act 1998 Replaces DPA 1994 EC directive 94/46/EC The Information Commissioner The courts.
Processing personal health data: the regulator’s perspective Ken Macdonald Assistant Commissioner Information Commissioner’s Office.
The Data Protection Act - Confidentiality and Associated Problems.
DATA PROTECTION ACT 1998 Became law on 1 March 2000 Only applies to the use of personal data, that is data which relates to an identifiable living individual,
The Data Protection Act What Data is Held on Individuals? By institutions: –Criminal information, –Educational information; –Medical Information;
Everyone has a duty to comply with the Act, including employers, employees, trainees, self-employed, manufacturers, suppliers, designers, importers of.
OPEN UP! Introduction to handling Freedom of Information requests.
Legal issues The Data Protection Act Legal issues What the Act covers The misuse of personal data By organizations and businesses.
Twelve Guiding Principles for the Regulation of Surveillance Camera Systems Presented by: Alastair Thomas Date: 23 rd October 2013.
PROTECTION OF PERSONAL DATA. OECD GUIDELINES: BASIC PRINCIPLES OF NATIONAL APPLICATION Collection Limitation Principle There should be limits to the collection.
Data Protection - Rights & Responsibilities Information Commissioner’s Office Orkney Practice Forum 4 th July 2007.
Data Protection Act The Data Protection Act (DPA) is a balance between rights of the DATA SUBJECT and obligations of the DATA CONTROLLER DATA CONTROLLER.
Information Systems Unit 3.
An Introduction to the Privacy Act Privacy Act 1993 Promotes and protects individual privacy Is concerned with the privacy of information about people.
An NZFFBS Training Module.  Objective 1  State the purpose and principles of the Privacy Act and the Code of Ethics.  Objective 2  Apply the principles.
The Freedom of Information Act and UCL Compliance Rosamund Cummings UCL FOI Officer
DATA PROTECTION ACT INTRODUCTION The Data Protection Act 1998 came into force on the 1 st March It is more far reaching than its predecessor,
© University of Reading Lee Shailer 06 June 2016 Data Protection the basics.
Can you share? Yes you can!! Angus Council Adult Protection Maureen H Falconer, Senior Policy Officer Information Commissioner’s Office.
Workshop Understanding your responsibilities under the Data Protection Act 1998 and the Freedom of Information Act 2000 Adele Rhodes Girling.
Data protection—training materials [Name and details of speaker]
Presented by Ms. Teki Akuetteh LLM (IT and Telecom Law) 16/07/2013Data Protection Act, 2012: A call for Action1.
Freedom of Information Act ‘What you need to know’ Corporate Information Governance Team Strategic Intelligence.
Protection of Personal Information Act An Analysis on the impact.
Clark Holt Limited (Co. No ), Hardwick House, Prospect Place, Swindon, SN1 3LJ Authorised and regulated by the Solicitors Regulation.
Data Protection and Freedom of Information. Objectives Describe the main points of the Data Protection Act 1998 and Freedom of Information Act 2000 Illustrate.
Section 4 Policies and legislation AQA ICT A2 Level © Nelson Thornes Section 4: Policies and Legislation Legislation – practical implications.
The Data Protection Act 1998
Research and the Data Protection and Freedom of Information Acts
Data Protection The Current Regime
The Data Protection Act 1998
Research Ethics Matthew Billington
Data Protection & Freedom of Information- An Introduction
Operations Director, CTRU
G.D.P.R General Data Protection Regulations
Introduction to Records Management, FOI & Data Protection
Data Protection principles
Data Protection What can I do? GDPR Principles General Data Protection
Freedom of Information
Presentation transcript:

Research and the Data Protection and Freedom of Information Acts

Data Protection Act 1998 and Freedom of Information Act 2000 DPA concerns personal data i.e. information from which a living individual can be identified FOI concerns all information – in any format – “held” by the institution even if it was created before 01/01/2005 when the Act came in to force

Research and the DPA Under Section 33 there are specific provisions in the Data Protection Act 1998 for the use of personal data in research Before using personal data in research, approval should be sought from the College’s Research Ethics Committee as part of the application process When collecting data the specific purpose(s) for doing so must be stated Researchers should adopt a system of anonymous coding (pseudo-anonymisation) as the identity of data subjects must not be given away without consent Appropriate security should be in place and note that there may be restrictions on where data can be stored

Research and the DPA All personal data must be held securely against loss, damage or unauthorised access Personal data must not be transferred out of the EEA unless that country has adequate protection – the USA, for example, is deemed not to. This will include storing data on servers (e.g. with cloud providers)

Research and the DPA Personal data used in research: –may be used for purposes beyond the originally stated purpose ( it’s good practice to inform data subjects if this happens) –must not be processed in such a way that substantial damage or substantial distress is, or is likely to be, caused to any data subject –can be retained indefinitely –is exempt from SARs (the right of access) - as long as published research does not identify individuals

Research and FOI (and EIR) Be aware that research data and final reports may be subject to FOI requests If a request is received it must be notified to the Records & Information Compliance ManagerRecords & Information Compliance Manager Similar regime – Environmental Information Regulations 2004 – applied to any information connected to environment, from soil to emissions

FOI Exemptions Possible exemption under s.22 (information intended for future publication) though must be a genuine intention to publish what has been requested Possible exemption under s.40 (personal data) – where individuals could be identified and data has only been provided for research purposes Possible exemption under s.41 (information provided in confidence) only if an agreement specifies that the data is property of a private funder and is being held in confidence Other relevant sections: s.12 (exceeds appropriate limit), s.14 (vexatious or repeated), s.43 (commercial interests)*

Research and FOI Providing a copy of information for FOI purposes does not mean that an individual or organisation has waived their intellectual property or moral rights* Deadline to respond to requests is 20 working days, therefore you should make arrangements to ensure that information can be retrieved in this time even if you are away Insert clauses in research contracts about ownership, copyright and FOI

Animal testing It is likely that exemptions will be able to be applied to prevent the disclosure of at least some information about animal testing under FOI For example s.40 exempts personal data such as researchers’ names being disclosed S.38 exempts information which may endanger the physical or mental health or safety of any individual

Any questions? Contact the Records & Information Compliance Manager Tel: (13) See also: Data Protection PolicyData Protection Policy