The Information Commissioner's Office (ICO) has published practical guidance on the Data Protection Act 1998 (DPA) in an attempt to demystify the DPA and to clearly set out and explain a data controller's responsibilities.
- The ICO's Guide to Data Protection was published on 26 November 2009.
- The guidance explains the principles of the DPA in simple terms.
- The guidance contains many practical examples, for example safeguarding personal information.
The Information Commissioner's Office has published a new guide to help businesses understand their obligations under the DPA (released on 26 November 2009). The guide explains the principles of the DPA in plain English and provides many practical examples.
Christopher Graham, the Information Commissioner, explained:
"the Data Protection Act provides us all with important privacy rights and the vast majority of businesses and organisations understand their legal obligations to protect our personal details. However there are still too many organisations playing fast and lose with personal data. Security breaches, inaccurate records and instances of data being held for too long are too common. This new guide will help organisations comply with the law and demystify data protection".
Stephen Alanbritis, Head of Public Affairs and the Federation of Small Businesses, said
"small businesses do not have time for pages and pages of jargon and gobbledygook, but getting data protection right makes good business sense. Data protection lapses cost reputations and can affect the bottom line. But, many organisations tell us that data protection law is difficult to understand. This new no-nonsense guide will help the business community to understand and comply with the law."
The guidance explodes a number of myths held about the DPA and its practical, business-based examples help data controllers to understand their responsibilities. The guide gives the following top tips for organisations:
- An organisation should say what it is going to do with personal information before individuals provide any details, unless it is obvious.
- Information should only be used for the reason for which it was collected in the first place.
- An organisation should not collect more information than is necessary.
- Information should be kept accurate and up-to-date. An organisation is asked to make changes to a person's details at the request of that individual.
- An organisation should not keep personal information if it is no longer needed.
- An organisation must comply with a request to provide copies of information held on an individual when asked.
- An organisation must keep personal information secure at all times.
- An organisation should not transfer personal details to another country unless adequate data protection arrangements are in place.
The guidance should help small businesses to understand their obligations under the DPA, in a clear, concise way. It is expressed as the Information ICO's interpretation of the DPA. Whilst the guidance states that it does not have the force of law, a business would be unwise in choosing to ignore it, since the Information Commissioner is the authority responsible for investigating any alleged breach of the DPA and ignoring its guidance would be taken into account.
The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.












