Home > Ask the Information Security Experts > Data privacy, compliance and risk management Questions & Answers > Complying with the UK Data Protection Act of 1998
Ask The Security UK Expert: Questions & Answers
EMAIL THIS

Complying with the UK Data Protection Act of 1998

Alan Calder EXPERT RESPONSE FROM: Alan Calder

Pose a Question
Other Security UK Categories
Meet all Security UK Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 10 January 2008
What are the key things I have to do to comply with the Data Protection Act?

>
EXPERT RESPONSE
There are a number of basic requirements and some that are rather more demanding. As a minimum, every organization that is going to process personal data (and this means any data relating to a living human being, not to an organization) must register with the Information Commissioner (www.ico.gov.uk) and describe, in the registration, what the purpose of processing this data is. It must be a permitted purpose. Registration is annually renewable and, once registered, you must comply with the purposes for which you've registered. That's the easy bit. The more complex bit is, in essence, that you must comply with the eight principles of the Data Protection Act. The eight principles are that personal information must be:
  • Fairly and lawfully processed
  • Processed for limited purposes
  • Adequate, relevant and not excessive
  • Accurate and up to date
  • Not kept for longer than is necessary
  • Processed in line with your rights
  • Secure
  • Not transferred to other countries without adequate protection
  • The ICO has comprehensive information (http://www.ico.gov.uk/for_organisations.aspx) and the BSI Data Protection Guide provides comprehensive guidance.


    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


    RELATED CONTENT
    Data privacy, compliance and risk management
    How to achieve laptop data security

    Compliance Regulations
    Firms rush to hit PCI compliance, but cut elsewhere
    Slow take-up of PCI reveals deeper ills
    Software licensing presents issues, challenges for enterprises
    ArcSight to take on UK compliance
    Data loss at the MoD and NHS shows need for stricter security policies
    Web 2.0 and e-discovery: Risks and countermeasures
    Security breaches and dual standards
    Breach disclosure regulation coming soon -- but not soon enough
    Tarnishing 'good names': How to stop a losing battle with identity thieves
    Security strategy research seeks to plug weaknesses

    Data Protection Solutions
    Latest data loss could cost EDS, and some staff, dearly
    Mobile technology may limit harm of laptop data loss
    Major security revamp seals NHS trust against data leakage
    PGP and IBM kickstart Bletchley Park rescue
    Outbound email under scrutiny as firms try to limit data loss
    Stronger penalties needed to force better data handling
    Lost Home Office memory stick an avoidable blunder
    Firms rush to hit PCI compliance, but cut elsewhere
    NHS trust fires manager for losing laptop
    Software licensing presents issues, challenges for enterprises

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    Basel II  (SearchSecurityUK.com)
    EU Data Protection Directive  (SearchSecurityUK.com)
    Financial Services Authority  (SearchSecurityUK.com)
    UK Identity Cards Act  (SearchSecurityUK.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



    Search and Browse the Expert Answer Center
    Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
    Browse our Expert Advice

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    SEARCH 
    TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




    All Rights Reserved, Copyright 2008, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts