Describe the Data Protection Act
states that organizations which store personal information must register and state the purpose for which they need the information
it lays down rules regarding how information is gathered,stored and shared
Who is a data subject
someone who has data about them stored somewhere, outside their direct control
Who is a data controller
person or company that collects and keeps data about people
Who is the data comisioner
is the person(and her office) who has powers to enforce the ACT
What are the rights of the data subjects
a right of subject access
a right of correction
a right to prevent distress
a right to prevent direct marketing
a right to prevent automatic decisions
a right of Complaint to the information Commissioner
A right to compensations
What are the responsibilieties of data controllers
Data must be kept secure.
Data stored must be relevant.
Data stored must be kept no longer than necessary.
Data stored must be kept accurate and up to date.
Data must be obtained and processed lawfully.
Data must be obtained and specified for lawful purposes.
Data must be processed within the data subject’s rights.
Data must not be transferred to countries that do not
have suitable data protection laws.
What are the duties of the data commissioner
any data controller who needs o store personal information must apply to Register with the Data Commissioner
A data subject can ask for the use of their personal data to be reviewed by the data commissioner who can enforce a ruling suing the act
The Commissioner may inspect a data controller’s computers to help in the investigation
What are some exemptions
Any personal data that is held for a national security reason is not
covered.
Personal data held for domestic purposes only at home.
What are some partial exemptions
The taxman or police
Medical Records
Partial exemptions:
Unpublished exam results
Employment references