Data Protection - Rights & Responsibilities Information Commissioner’s Office Orkney Practice Forum 4 th July 2007.

Slides:



Advertisements
Similar presentations
Introduction to basic principles of Regulation (EC) 45/2001 Sophie Louveaux María Verónica Pérez Asinari.
Advertisements

Data Protection Information Management / Jody McKenzie.
The Data Protection (Jersey) Law 2005.
Getting data sharing right for every child
Data Protection.
DATA PROTECTION and Research University Research Ethics Committee – David Cauchi Office of the Data Protection Commissioner.
What does the Data Protection Act do? It sets standards which must be satisfied when obtaining, recording, holding, using, disclosing or disposing of.
Data Protection Data Protection Acts 1988 & 2003 Directive 95/46/EC Privacy.
National Smartcard Project Work Package 8 – Information Law Report.
Data Protection Act Description The Data Protection Act controls how your personal information can be used and protects from the misuse of your.
DATA PROTECTION AND PATIENT CONFIDENTIALITY IN RESEARCH Nic Drew Data Protection Manager University Hospital of Wales   
Audiences NI Data Protection Workshop
Data Protection Paul Veysey & Bethan Walsh. Introduction Data Protection is about protecting people by responsibly managing their data in ways they expect.
Data Protection Overview
The Data Protection Act
The ICO and the DPA Ken Macdonald Assistant Commissioner Information Commissioner’s Office ScotStat Public Sector Analysts Network 30 th September 2010.
 The Data Protection Act 1998 is an Act of Parliament which defines UK law on the processing of data on identifiable living people and it is the main.
The Information Commissioner’s Office David Evans.
Data Protection and You Your Rights & The Law Registration Basics Other Activities Disclaimer: This presentation only provides an introductory info. Please.
The Data Protection Act 1998 The Eight Principles.
OCR Nationals Level 3 Unit 3.  To understand how the Data Protection Act 1998 relates to the data you will be collecting, storing and processing  To.
Data Protection: An enabler? David Freeland, Senior Policy Officer 23 October 2014.
Data Protection Act AS Module Heathcote Ch. 12.
Data Protection Act & Freedom of Information Simon Mansell Corporate Governance and Information Team.
Data Protection Corporate training Data Protection Act 1998 Replaces DPA 1994 EC directive 94/46/EC The Information Commissioner The courts.
Processing personal health data: the regulator’s perspective Ken Macdonald Assistant Commissioner Information Commissioner’s Office.
What is personal data? Personal data is data about an individual which they consider to be private.
The Data Protection Act - Confidentiality and Associated Problems.
DATA PROTECTION ACT 1998 Became law on 1 March 2000 Only applies to the use of personal data, that is data which relates to an identifiable living individual,
The Data Protection Act What Data is Held on Individuals? By institutions: –Criminal information, –Educational information; –Medical Information;
Data Protection and Records Management. Key Responsibilities - Record Management Keep Information Accurate Disclose only if compatible with purpose for.
Legal issues The Data Protection Act Legal issues What the Act covers The misuse of personal data By organizations and businesses.
Data Protection Property Management Conference. What’s it got to do with me ? As a member of a management committee responsible for Guiding property you.
The Data Protection Act What the Act covers The misuse of personal data by organisations and businesses.
Introduction Data protection is relevant to every individual, business or organisation today, not just Local Government. As well as protecting privacy,
THE DATA PROTECTION ACT Data Protection Act 1998 DPA 1. Reasons2. People3. Principles 4. Exemptions 4 key points you need to learn/understand/revise.
Data Protection Act The Data Protection Act (DPA) is a balance between rights of the DATA SUBJECT and obligations of the DATA CONTROLLER DATA CONTROLLER.
Data Protection and research Rachael Maguire Records Manager.
DATA PROTECTION ACT (DPA). WHAT IS THE DATA PROTECTION ACT?  The Data Protection Act The Data Protection Act (DPA) gives individuals the right.
What is the Data Protection Act (DPA)? 1998 The Data Protection Act 1998 seeks to strike a balance between the rights of individuals and the sometimes.
DATA PROTECTION ACT INTRODUCTION The Data Protection Act 1998 came into force on the 1 st March It is more far reaching than its predecessor,
Session 11 Data protection. 1 Contents Part 1: Introduction Part 2: Applicability and responsibility Part 3: Our procedures on data protection Part 4:
DATA PROTECTION AND RUNNING A COMPLIANT PUB WATCH SCHEME Nigel Connor Head of Legal –JD Wetherspoon PLC.
© University of Reading Lee Shailer 06 June 2016 Data Protection the basics.
Can you share? Yes you can!! Angus Council Adult Protection Maureen H Falconer, Senior Policy Officer Information Commissioner’s Office.
Getting data sharing right for every child Maureen H Falconer Senior Policy Officer Information Commissioner’s Office.
Workshop Understanding your responsibilities under the Data Protection Act 1998 and the Freedom of Information Act 2000 Adele Rhodes Girling.
Data protection—training materials [Name and details of speaker]
Sharing Personal Data ‘What you need to know’ Corporate Information Governance Team Strategic Intelligence.
Practical implications of the Data Protection Bill By John Robinson Data Protection Co-Ordinator South Bucks NHS Trust.
Presented by Ms. Teki Akuetteh LLM (IT and Telecom Law) 16/07/2013Data Protection Act, 2012: A call for Action1.
Clark Holt Limited (Co. No ), Hardwick House, Prospect Place, Swindon, SN1 3LJ Authorised and regulated by the Solicitors Regulation.
Data Protection Laws in the European Union John Armstrong CMS Cameron McKenna.
Students’ Unions 2011 Data Protection and Students’ Unions Mairead O’Reilly 19 July 2011.
The Data Protection Act 1998
PowerPoint presentation
Trevor Ellis Trainee Programmer (1981 – 28 years ago)
Data Protection The Current Regime
The Data Protection Act 1998
Data Protection Legislation
GDPR Road map to Compliance.
Data Protection & Freedom of Information- An Introduction
GENERAL DATA PROTECTION REGULATION (GDPR)
Data Protection Act.
G.D.P.R General Data Protection Regulations
Data Protection and Running a Compliant Pub Watch SCHeme
Data Protection principles
Data Protection and You
Data Protection What’s new about The General Data Protection Regulation (GDPR) May 2018? Call Kerry on Or .
What is the Data Protection Act (DPA)? 1998
Presentation transcript:

Data Protection - Rights & Responsibilities Information Commissioner’s Office Orkney Practice Forum 4 th July 2007

The Data Protection Act 1998 Data Protection Applies to personal information only Covers all organisations Gives individual rights over their information Same Act north and south of the border

The Data Protection Act 1998 Relates to personal data (ie, that which can identify an individual) held electronically or in structured manual records Stricter controls over “sensitive personal data” (eg, race/ethnicity, religion, criminal history, medical records) Provides a records management framework

The Data Protection Act 1998 Organisations must ensure that data is: “processed” fairly and lawfully and for (a) specified lawful purpose(s) adequate, relevant, not excessive, accurate and kept up to date kept for no longer than is necessary kept secure

The Data Protection Act 1998 Organisations must also : Respect the rights of data subjects Organisations must not : Transfer data out of the EEA unless appropriate safeguards exist to protect it

The Data Protection Act 1998 Some organisations must : notify the Commissioner of the sources of data, the purposes for which it will be used and the disclosures which may be made of it. £35 annual fee

The Data Protection Act 1998 Fair and lawful processing: Data subjects must be told what their data is being used for (fair processing) Conditions allowing processing must be met (lawful processing)

The Data Protection Act 1998 Conditions for lawful processing of personal data: Consent Contract Legal obligation Vital interests Public interest Legitimate interest

The Data Protection Act 1998 Additional conditions for lawful processing of sensitive personal data: Explicit consent Compliance with employment law Vital interests Not-for-profit organisation Information made publicly available Legal advice Public functions Medical purposes Equal Opps Monitoring

The Data Protection Act 1998 Individual rights: Access (Section 7 / Subject Access Request) Prevention of processing causing distress Prevention of direct marketing Prevention of automated decision making Rectification, blocking, erasure, destruction Compensation Request for assessment

The Data Protection Act 1998 Offences Unlawfully obtaining or disclosing personal data) Selling of personal data Failure to notify / notify changes Failure to comply with a Notice from the Commissioner

Gathering Information

Sharing Information

Providing information

The Data Protection Act 1998 Contact The Information Commissioner’s Office 28 Thistle St EDINBURGH EH2 1 EN