Data protection legislation and regulations govern how businesses and organisations collect, process and store an individual’s data. The Data Protection Act 2018 and the European General Protection Regulation (GDPR) are key pieces of legislation that instruct organisations in how it handles and processes personal data.
Personal data is any data which is able to identify or make an individual identifiable. Information can include their name, address, date of birth or information like an employee number given to an individual’s employment record, which makes them identifiable.
Business that are data controllers, that is to say they have control over the data and how it is processed, must register with the Information Commissioner’s Office if the processing of data goes beyond payroll admin or sales and purchase invoicing. The principles of data protection include:
Lawful, transparent, and fair – it should be understood how and why the data is collected and that it is used legally.
Purpose limitation and data minimisation – minimal information should be requested and kept only for the purpose in the limited time for which it was received.
Accuracy – business would ensure that the data is accurate and they should amend or remove any inaccurate information they hold.
Storage limitation – Businesses should only retain one information for the purpose it was granted and should be deleted thereafter
Integrity and confidentiality – data should be securely stored and protected from accidental damage, deletion, or unlawful activity. Data protection should govern the conditions of data management and systems should have protections to keep the data secure.