data protection corporate training 2012. data protection act 1998 replaces dpa 1994 ec directive...

40
Data Protection Corporate training 2012

Upload: sabina-gordon

Post on 13-Jan-2016

215 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Data Protection Corporate training 2012. Data Protection Act 1998 Replaces DPA 1994 EC directive 94/46/EC The Information Commissioner The courts

Data Protection

Corporate training 2012

Page 2: Data Protection Corporate training 2012. Data Protection Act 1998 Replaces DPA 1994 EC directive 94/46/EC The Information Commissioner The courts
Page 3: Data Protection Corporate training 2012. Data Protection Act 1998 Replaces DPA 1994 EC directive 94/46/EC The Information Commissioner The courts
Page 4: Data Protection Corporate training 2012. Data Protection Act 1998 Replaces DPA 1994 EC directive 94/46/EC The Information Commissioner The courts
Page 5: Data Protection Corporate training 2012. Data Protection Act 1998 Replaces DPA 1994 EC directive 94/46/EC The Information Commissioner The courts

Data Protection Act 1998

• Replaces DPA 1994

• EC directive 94/46/EC

• The Information Commissioner

• The courts

Page 6: Data Protection Corporate training 2012. Data Protection Act 1998 Replaces DPA 1994 EC directive 94/46/EC The Information Commissioner The courts

Data Protection Act 1998

• Regulates the processing of data

• Gives rights to individuals

Page 7: Data Protection Corporate training 2012. Data Protection Act 1998 Replaces DPA 1994 EC directive 94/46/EC The Information Commissioner The courts

How does it affect me?

• Fylde BC as a “data controller” has responsibilities for data under its control

• All employees handling data have responsibility

Page 8: Data Protection Corporate training 2012. Data Protection Act 1998 Replaces DPA 1994 EC directive 94/46/EC The Information Commissioner The courts

Concepts we will cover

• Data• Personal Data• Sensitive Personal Data• The eight data protection principles• Subject access rights

Page 9: Data Protection Corporate training 2012. Data Protection Act 1998 Replaces DPA 1994 EC directive 94/46/EC The Information Commissioner The courts

Data

• Any recorded information held by a public authority

• Narrower definition outside the public sector

Page 10: Data Protection Corporate training 2012. Data Protection Act 1998 Replaces DPA 1994 EC directive 94/46/EC The Information Commissioner The courts

Personal data

• Living individual• Identified from data - or from other information• Opinions• Intentions

Page 11: Data Protection Corporate training 2012. Data Protection Act 1998 Replaces DPA 1994 EC directive 94/46/EC The Information Commissioner The courts

Sensitive personal data

• Race or ethnicity• Political opinions• Religion• Union membership• Health• Sexual life• Offences

Page 12: Data Protection Corporate training 2012. Data Protection Act 1998 Replaces DPA 1994 EC directive 94/46/EC The Information Commissioner The courts

Processing• Obtaining• Recording• Holding• Organising• Adapting• Altering• Retrieving• Consulting• Using

• Disclosing• Transmitting• Disseminating• Making available• Aligning• Combining• Blocking• Erasing• Destroying

Page 13: Data Protection Corporate training 2012. Data Protection Act 1998 Replaces DPA 1994 EC directive 94/46/EC The Information Commissioner The courts

The data protection principles• Personal data shall be:

– processed fairly and lawfully– used only for specified and lawful purposes– adequate, relevant and not excessive– accurate

– not be kept for longer than necessary

– processed in line with rights of data subjects

– protected against tampering and loss

– not transferred to certain countries

Page 14: Data Protection Corporate training 2012. Data Protection Act 1998 Replaces DPA 1994 EC directive 94/46/EC The Information Commissioner The courts

The first principle: Fair processing

“Personal data shall be processed fairly and lawfully and, in particular, shall not be processed unless [at least one of certain] conditions are met…”

Page 15: Data Protection Corporate training 2012. Data Protection Act 1998 Replaces DPA 1994 EC directive 94/46/EC The Information Commissioner The courts

The first principle: Fair processing

“Personal data shall be processed fairlyAND

lawfully AND

in particular, shall not be processed unless [at least one of certain] conditions are met…”

Page 16: Data Protection Corporate training 2012. Data Protection Act 1998 Replaces DPA 1994 EC directive 94/46/EC The Information Commissioner The courts

The first principle: Fair processing

• “Fairly”– Consequences to subject– Fair processing information

• “Lawfully”– Powers– Legitimate expectation– Human rights

Page 17: Data Protection Corporate training 2012. Data Protection Act 1998 Replaces DPA 1994 EC directive 94/46/EC The Information Commissioner The courts

The first principle: The conditions for fair processing• Consent of subject

Page 18: Data Protection Corporate training 2012. Data Protection Act 1998 Replaces DPA 1994 EC directive 94/46/EC The Information Commissioner The courts

The first principle: Fair processing

• Consent– Active communication– Freely given– Not by default– Appropriate to the circumstances

Page 19: Data Protection Corporate training 2012. Data Protection Act 1998 Replaces DPA 1994 EC directive 94/46/EC The Information Commissioner The courts

The first principle: The conditions for fair processing

• Consent of subject• Contracts• Legal obligations• Public interest conditions• Legitimate interests: Balance• Necessity test

Page 20: Data Protection Corporate training 2012. Data Protection Act 1998 Replaces DPA 1994 EC directive 94/46/EC The Information Commissioner The courts

Sensitive personal data: Extra conditions

• “Explicit” consent

• Employer’s obligations

• Vital interests

• Political or religious bodies

• Public domain

• Legal proceedings

• Administration of justice

• Health purposes…

Page 21: Data Protection Corporate training 2012. Data Protection Act 1998 Replaces DPA 1994 EC directive 94/46/EC The Information Commissioner The courts

Sensitive personal data: Extra restrictions

• Equalities• Detection or prevention of crime• Public protection• Counselling services• Insurance• Police

Page 22: Data Protection Corporate training 2012. Data Protection Act 1998 Replaces DPA 1994 EC directive 94/46/EC The Information Commissioner The courts

The second principle: Specified purposes

“Personal data shall be obtained only for one or more specified and lawful purposes and shall not be further processed in any manner incompatible with that purpose or those purposes”

Page 23: Data Protection Corporate training 2012. Data Protection Act 1998 Replaces DPA 1994 EC directive 94/46/EC The Information Commissioner The courts

The second principle: Specified purposes

Purposes can be satisfied by:

• Notice to data subject

• Registration with the Information Commissioner

Page 24: Data Protection Corporate training 2012. Data Protection Act 1998 Replaces DPA 1994 EC directive 94/46/EC The Information Commissioner The courts
Page 25: Data Protection Corporate training 2012. Data Protection Act 1998 Replaces DPA 1994 EC directive 94/46/EC The Information Commissioner The courts

Whose responsibility?

Page 26: Data Protection Corporate training 2012. Data Protection Act 1998 Replaces DPA 1994 EC directive 94/46/EC The Information Commissioner The courts

The third principle: Proportionality

“Personal data shall be adequate, relevant and not excessive in relation to the purpose or purposes for which they are processed”

Page 27: Data Protection Corporate training 2012. Data Protection Act 1998 Replaces DPA 1994 EC directive 94/46/EC The Information Commissioner The courts

The third principle: Proportionality

• Minimum of data for the purpose

• Cannot hold information “just in case”

• Should not be held longer than needed

Page 28: Data Protection Corporate training 2012. Data Protection Act 1998 Replaces DPA 1994 EC directive 94/46/EC The Information Commissioner The courts

The fourth principle: Accuracy

“Personal data shall be accurate and, where necessary, kept up to date”

Page 29: Data Protection Corporate training 2012. Data Protection Act 1998 Replaces DPA 1994 EC directive 94/46/EC The Information Commissioner The courts

The fourth principle: Accuracy

• Reasonable steps

• Right of data subject to mark inaccuracies

• Data must be updated “where necessary”

Page 30: Data Protection Corporate training 2012. Data Protection Act 1998 Replaces DPA 1994 EC directive 94/46/EC The Information Commissioner The courts

The fifth principle: Deleting old data

“Personal data processed for any purpose or purposes shall not be kept for longer than is necessary for that purpose or those purposes”

Page 31: Data Protection Corporate training 2012. Data Protection Act 1998 Replaces DPA 1994 EC directive 94/46/EC The Information Commissioner The courts

The fifth principle: Deleting old data

• Need for system of review

• Depends on purpose data was held

• Exception for historical, statistical or research purposes

Page 32: Data Protection Corporate training 2012. Data Protection Act 1998 Replaces DPA 1994 EC directive 94/46/EC The Information Commissioner The courts

The sixth principle: Subjects’ rights

“Personal data shall be processed in accordance with the rights of data subjects under this Act”

Page 33: Data Protection Corporate training 2012. Data Protection Act 1998 Replaces DPA 1994 EC directive 94/46/EC The Information Commissioner The courts

The sixth principle: Subjects’ rights

• Subject access requests

• Processing likely to cause damage or distress– notice procedure

• Processing for direct marketing

• Automatic decision-taking

Page 34: Data Protection Corporate training 2012. Data Protection Act 1998 Replaces DPA 1994 EC directive 94/46/EC The Information Commissioner The courts

Subject access request

• Made by data subject in writing (including e-mail)

• Fee of £10

• Data controller must:– say if he holds

personal data about that person

– provide a copy of that data

– say why they are being processed and

– to whom they may be disclosed

Page 35: Data Protection Corporate training 2012. Data Protection Act 1998 Replaces DPA 1994 EC directive 94/46/EC The Information Commissioner The courts

Subject access request

• Promptly, or within 40 days• Exceptions:

– Disproportionate effort– Affect on health– Third party information– Unstructured personal data UNLESS

• The data is identified; and• Within cost limit

Page 36: Data Protection Corporate training 2012. Data Protection Act 1998 Replaces DPA 1994 EC directive 94/46/EC The Information Commissioner The courts

Third party information

“Information relating to an individual other than the the data subject who can be identified by that information”

• Where the third party has consented

• Reasonable in all the circumstances– duty of confidentiality

– whether consent sought

– Anonimysing

Page 37: Data Protection Corporate training 2012. Data Protection Act 1998 Replaces DPA 1994 EC directive 94/46/EC The Information Commissioner The courts

The seventh principle: Tampering and loss

“Appropriate technical and organisational measures shall be taken against unauthorised or unlawful processing of personal data and against accidental loss or destruction of, or damage to, personal data”

Page 38: Data Protection Corporate training 2012. Data Protection Act 1998 Replaces DPA 1994 EC directive 94/46/EC The Information Commissioner The courts

The seventh principle: Tampering and loss

• Risk management• Security policy• Access to PCs• Passwords

• Authentication of callers

• Backups• Virus protection• Training

Page 39: Data Protection Corporate training 2012. Data Protection Act 1998 Replaces DPA 1994 EC directive 94/46/EC The Information Commissioner The courts

The eighth principle: Data Transfer

“Personal data shall not be transferred to a country of territory outside the European Economic Area, unless that country or territory ensures an adequate level of protection of the rights and freedoms of data subjects in relation to the processing of personal data”

Page 40: Data Protection Corporate training 2012. Data Protection Act 1998 Replaces DPA 1994 EC directive 94/46/EC The Information Commissioner The courts

Further information• Your line manager

• Tracy Morrison or Ian Curtis

• www.ico.gov.uk