Principles Of Data Protection

421 Words2 Pages
The Eight Principles of Data Protection Personal data must be: 1. Processed fairly and lawfully. There should be no surprises so inform people why the data is being collected about them, what is being done with it and with whom it is likely to be shared. Be open, honest and clear. 2. Processed for specific purposes. Only use it for the purpose(s) for which it was obtained and only share information if you are certain that it is appropriate and necessary to do so. If in doubt, check first. 3. Adequate, relevant and not excessive. Only collect and keep information that is required; it is not acceptable to hold information unless you have a view as to how it will be used. Data should not be collected ‘just in case’. 4. Accurate and kept up-to-date. Ensure when inputting data that it is done accurately; check existing records before adding new ones and avoid creating duplicate records. 5. Not kept for longer than necessary. Follow retention guidelines: check the retention policy of the organisation, check the disposal policy and dispose of information correctly. 6. Processed in accordance with the rights of data subjects (ie service users) which are: i) the right of access to personal information ii) the right to prevent processing for direct marketing purposes iii) the right to prevent processing likely to cause substantial damage or distress iv) rights in relation to automated decision-making v) the right to seek compensation for any damage or distress caused by the failure of a Data Controller to comply with the requirements of the Act vi) the right to take action to rectify, block, erase or destroy inaccurate data 7. Protected by appropriate security. There are two aspects to this: i) Practical issues: a) Use a suitable location for secure faxes and always keep confidential papers locked away. b) Ensure confidential
Open Document