What does the Data Protection Act mean for my business?

We often hear stories in the news about people’s personal data being leaked or hacked into.  This section looks to guide you through some of the fundamental basics around Data Protection that you need to be aware of. 

What does the Data Protection Act mean by Data?

Data refers to any information held about any person, whether an employee, a job candidate, a freelancer or customer. This could include but is not limited to:

  • name and address
  • telephone numbers
  • bank account details
  • information about ethnic origins
  • religious beliefs
  • health
  • criminal records.

What are the key rules of data protection?

The data protection act has eight key principles that must be adhered to.

  1. used fairly and lawfully
  2. used for limited, specifically stated purposes
  3. used in a way that is adequate, relevant and not excessive
  4. accurate
  5. kept for no longer than is absolutely necessary
  6. handled according to people’s data protection rights
  7. kept safe and secure
  8. not transferred outside the European Economic Area without adequate protection.

Every business must have a Data Controller. A data controller is a nominated person in a compnany who applies to the data commissionner fo permission to store and use personal data. The data controller must keep to the eight key principles. 

You will need to nominate a Data Controller and register your Data Controller with the Information Commissioners office. More information can be found in Next Steps at the end of this article. 

Quiz: What rights does an employee have to see their personnel records?