The Data Protection Act - an absolute right to ask but a qualified right to receive Maureen H Falconer Senior Policy Officer, ICO CELCIS, Scottish University.

Slides:



Advertisements
Similar presentations
Academic Services Division Rights & Responsibilities Academic Services Division Sam Kingston Academic Services Officer Theresa Pollard Academic Services.
Advertisements

The Legislative Position in Scotland Environmental Information (Scotland) Regulations 2004 SSI 2004 No.520 Professor Colin Reid, School of Law, University.
Data Protection & Privacy in the Information Age COMNET – Legal Frameworks for ICTs Malta 2013 Dr Antonio Ghio Dr Jeanine Rizzo.
DATA PROTECTION and Research University Research Ethics Committee – David Cauchi David Cauchi Office of the Commissioner for Data Protection.
Data Protection and Freedom of Information
Protection of privacy for all Students!
Data Protection Information Management / Jody McKenzie.
The Data Protection (Jersey) Law 2005.
Getting data sharing right for every child
Data Protection.
Patient Access To Health Records. Lucy Etukakpan..
DATA PROTECTION and Research University Research Ethics Committee – David Cauchi Office of the Data Protection Commissioner.
What does the Data Protection Act do? It sets standards which must be satisfied when obtaining, recording, holding, using, disclosing or disposing of.
Data Protection and Freedom of Information The Warwick Network 12 August 2015 Natalie Snodgrass – Administrative Officer, University Secretary’s Office.
Data Protection Overview
The ICO and the DPA Ken Macdonald Assistant Commissioner Information Commissioner’s Office ScotStat Public Sector Analysts Network 30 th September 2010.
1 OVERVIEW PRESENTATION FREEDOM OF INFORMATION (SCOTLAND) ACT 2002.
Exemptions and the Public Interest Test Louise Townsend - Masons.
Data Protection for Church of Scotland Congregations
Data Sharing and Good Practice Maureen H Falconer Sr Policy Officer Information Commissioner’s Office.
Updated 12/02/2007 Relevant Laws Relevant Laws ContraceptionContraception, Sterilisation and Abortion Act 1977 (CS&A Act) CS & A Amendment 1978, 1990 AbortionCare.
2010 Case Study – A Pig of a Day Document Risk Management.
Data Protection and You Your Rights & The Law Registration Basics Other Activities Disclaimer: This presentation only provides an introductory info. Please.
Public rights of access to information Grisilda Ponniah, Corporate Information Governance Manager Mary Elliott, FOI Officer Legal & Democratic Services.
Elma Graham. To understand what data protection is To reflect on how data protection affects you To consider how you would safeguard the data of others.
707 KAR 1:360 Confidentiality of Information. Section 1: Access Rights 1) An LEA shall permit a parent to inspect and review any education records relating.
DATA PROTECTION OFFICE {PMO} “OVERVIEW OF THE FUNDAMENTAL ASPECTS OF THE RIGHT OF ACCESS“ Presented by The Commissioner Mrs D. Madhub To Mutual Aid Association.
OCR Nationals Level 3 Unit 3.  To understand how the Data Protection Act 1998 relates to the data you will be collecting, storing and processing  To.
Data Protection: An enabler? David Freeland, Senior Policy Officer 23 October 2014.
SUBJECT ACCESS Data Subject Access – A Legal Right.
Data Protection & FOI Data Protection: Background Human Right to Privacy Unenumerated right under Irish Constitution Explicit right under European Convention.
Data Protection Act & Freedom of Information Simon Mansell Corporate Governance and Information Team.
Data Protection Corporate training Data Protection Act 1998 Replaces DPA 1994 EC directive 94/46/EC The Information Commissioner The courts.
Processing personal health data: the regulator’s perspective Ken Macdonald Assistant Commissioner Information Commissioner’s Office.
OPEN UP! Introduction to handling Freedom of Information requests.
Internal Review under the Freedom of Information Law 2007 Carole Excell, FOI Coordinator.
IM NETWORK MEETING 20 TH JULY, 2010 CONSULTATION WITH 3 RD PARTIES.
12/12/2015 Data Protection Act /12/2015 The DP Act A law that protects personal privacy and upholds individual’s rights Anyone who handles personal.
ANONYMISATION Research Data Management. c Research Data Management Sensitive Data Sensitive Data is information covering: The racial or ethnic origin.
Introduction Data protection is relevant to every individual, business or organisation today, not just Local Government. As well as protecting privacy,
Data Practices in Minnesota December Outline for this presentation Minnesota data practices laws Classification of government data Government entity.
Data Protection Act The Data Protection Act (DPA) is a balance between rights of the DATA SUBJECT and obligations of the DATA CONTROLLER DATA CONTROLLER.
DATA PROTECTION ACT (DPA). WHAT IS THE DATA PROTECTION ACT?  The Data Protection Act The Data Protection Act (DPA) gives individuals the right.
DATA PROTECTION ACT INTRODUCTION The Data Protection Act 1998 came into force on the 1 st March It is more far reaching than its predecessor,
GCSE ICT Data and you: The Data Protection Act. Loyalty cards Many companies use loyalty cards to encourage consumers to use their shops and services.
Getting data sharing right for every child Maureen H Falconer Senior Policy Officer Information Commissioner’s Office.
Sharing Information Legally Lindsay Ould London Borough of Lewisham.
Sharing Personal Data ‘What you need to know’ Corporate Information Governance Team Strategic Intelligence.
Practical implications of the Data Protection Bill By John Robinson Data Protection Co-Ordinator South Bucks NHS Trust.
Presented by Ms. Teki Akuetteh LLM (IT and Telecom Law) 16/07/2013Data Protection Act, 2012: A call for Action1.
Clark Holt Limited (Co. No ), Hardwick House, Prospect Place, Swindon, SN1 3LJ Authorised and regulated by the Solicitors Regulation.
Data Protection and Freedom of Information. Objectives Describe the main points of the Data Protection Act 1998 and Freedom of Information Act 2000 Illustrate.
Introduction to Data Protection Plan »Brief Introduction to Data Protection  Example  Principles  P3, 4, 7  Sensitive Data  Conditions for Processing.
Students’ Unions 2011 Data Protection and Students’ Unions Mairead O’Reilly 19 July 2011.
Monique Jefferson & Nadine Mather
Subject Access Request Webinar Friday 20 May 11am
Handling Tricky Requests for Pupil Information
Data Protection and Confidentiality
Data Protection The Current Regime
Data Protection & Freedom of Information- An Introduction
Public Sector Organisations - are you GDPR ready?
GENERAL DATA PROTECTION REGULATION (GDPR)
Data Protection: Your Rights as a Data Subject
New Data Protection Legislation
Data Protection principles
Data Protection and You
A Framework for Compliance
Data Protection for SDS Employers Alison Johnston Lead Policy Officer (Scotland) Information Commissioner’s Office.
“Seven-minute Staff Meeting”
Data protection & FOIA considerations
Presentation transcript:

The Data Protection Act - an absolute right to ask but a qualified right to receive Maureen H Falconer Senior Policy Officer, ICO CELCIS, Scottish University Insight Institute 23 September 2013

The Right of Subject Access Section 7 Provides the right to find out: what personal information is held about you by an organisation; why it is being held; and to whom it is, or is likely to be, disclosed.

What is personal data? Personal data relate to a living individual who can be identified from those data and/or other information and includes opinions and intentions of the data controller or any other person in respect of the individual.

What is sensitive personal data? Sensitive personal data relate to racial or ethnic origin, political opinions, religious beliefs, trade union membership, health, sexual life and criminal activity.

Making a subject access request Must be made in writing (recordable format); Must provide proof of identity; May be charged a fee; May be asked for more information

Receiving a subject access request Must be made in writing (recordable format); Must verify identity; May charge a fee; May ask for more information; Must respond within 40 calendar days; May redact third party information; May rely on specific exemption(s).

Subject Access & Third Party Data Section 7(4) Where an organisation cannot comply with a request without disclosing information relating to another individual who can be identified from that data, there is no obligation to comply with the request unless: The other individual has consented to the disclosure; or It is reasonable in all the circumstances to comply with the request without the consent of the other individual; or The other individual is an appointed Safeguarder, the Principal Reporter or a social worker engaged in the case.

When is it reasonable in all the circumstances? Section 7(6) Provides a non exhaustive list of factors for organisations to consider: Any duty of confidence owed to the individual Any steps taken to obtain consent Whether the individual is capable of giving consent Any express refusal of consent. Confidentiality: Arises where information which is not generally available to the public is provided with the expectation that it will be kept confidential: Solicitor/Client, Doctor/Patient, Social Worker/Client, etc.

Reasonable in the circumstances – other factors Information already known to the requestor: Is the information already known by the person making the request, is it generally available to the public or has it previously been made available to the person making the request? Circumstances of the request: Regard should be had to the importance of the information to the individual against the importance of maintaining the confidentiality of the third party.

Redaction of third party information Section 7(5) Third parties include information relating to another individual which identifies that individual as the source of the information. It does not excuse an organisation from providing as much information as possible without disclosing third party data, whether by redaction of identifying information or other means; e.g. summarising the personal data. The individual making the request is entitled to the personal data held - not necessarily the document in which it is held.

SI 2000/415 exemption Applies to: Data processed by a local authority in connection with its social work and education welfare functions and health boards to whom such data are passed; Data processed by a local authority which has been supplied by the Principal Reporter of Scottish Children’s Reporter Administration; and Data processed by the Children’s Hearing system where the information may be withheld by the Hearing in whole or in part.

SI 2000/415 exemption Subject access - to the extent to which release of the data would be likely to prejudice the carrying out of social work if it is likely to cause serious harm to anyone’s physical or mental health; Specific exemptions: In relation to social work reports supplied to Children’s Hearings - fair processing and subject access unless Hearing allows; In relation to the Principal Reporter - subject access unless (s)he allows; In relation to parents/guardians/court appointee acting on behalf of a child/young person - subject access to the extent that the child/young person would not expect, or has expressly forbade, the data to be disclosed.

Subject Access & Category (e) Data Section 9A Unstructured data – not automated, with a view to being automated, a relevant filing system or none of the above but forms part of a social work record. Requester must provide a description of the data requested; Public Authority need not comply if the estimated cost to do so would exceed £600

Subject Access & Disproportionate Effort Section 8(2): The obligation to respond to a subject access request must be complied with by supplying the data subject with a copy of the information in permanent form unless – The supply of such a copy is not possible or would involve disproportionate effort, or The individual agrees otherwise. Note: it does not apply to searching for the data. Even where providing the information in permanent form may involve disproportionate effort – the data controller should still try and comply with the request in some other way. The right of subject access is central to the DPA.

Keep in touch Scotland Office: 45 Melville Street Edinburgh EH3 7HL T: E: Subscribe to our e-newsletter at or find us on…