When does the Act apply?
The Act applies whenever a person or organisation processes personal data.
The words “processing” and “personal data” both have technical meanings under the Act, but generally it is sufficient to know that:
What does the Act require?
The Act requires the data controller (the person or organisation who determines the purposes for which the personal data is used) to ensure the personal data is processed in accordance with the following 8 principles:
Data protection principles – data must be:
If you are a data controller, you must register with the Information Commissioner, unless you hold and use personal information only for the following purposes: staff administration and payroll; marketing your own business; or accounts and records (ie records of work done and accounts for goods and services that you provide).
Fair processing
In order to satisfy the first data principle (“fair and lawful processing”) the data controller must ensure that the processing meets one of the following conditions:
Fair processing conditions - that:
Sensitive personal data
Where the data controller processes “sensitive personal data”, one of the following further conditions must be met.
Fair processing conditions for sensitive personal data – that:
What rights do individuals have under the Act?
Individuals are entitled to request a copy of their personal data from a data controller. The request must be made by the data subject in writing. There are certain limited exemptions which can justify the data controller not providing a copy of some personal data.
Individuals also have the following additional rights:
The Information Commissioner’s Office has powers of investigation andm enforcement in relation to complaints made by members of the public regarding non-compliance with the Act. Individuals may also have the right to claim compensation through the courts in some cases
How can we assist?
For Further information please contact:
Austin Flynn by email or telephone 0131 247 1260
Callum Murray by email or telephone 0131 247 1237