SlideShare a Scribd company logo
Data Protection and IDEA
Joanne Bone & Neil Bentley
Irwin Mitchell
11 May 2004
Why Is Data Protection
Important?
• Data Protection Act 1998
• Overseen by the UK’s Information
Commissioner
• Potential Civil and Criminal Liability
Why Is Data Protection
Important?
• Criminal Liability
• Fines for breach
– Up to £5000 in Magistrates’ Court
– Unlimited in Crown Court
• Company officers, directors and
managers can be personally liable
Why Is Data Protection
Important?
• Civil Liability
• Any breach of the Act is actionable
• Compensation for damage and/or
distress
• In practice Courts are awarding
damages for breach of the Act
So When Does The Data
Protection Act Apply?
• The Act applies to the PROCESSING
of PERSONAL DATA
What Is Personal Data?
• Personal data can be any information
which relates to a living individual who
is identifiable from that data alone or in
conjunction with other data
• Both paper and electronic records can
be covered
What Is Personal Data?
• Durant v Financial Services Authority
• Definition of personal data interpreted
by the Court in a more restrictive way
• Information now only personal data
where it affects the individual’s privacy
– Is the information biographical?
– Is the information focused on the
individual?
What Is Personal Data?
• Payroll/salary details?
• Internet logs?
• Health records?
• e-mails?
• Electoral register?
• CCTV images?
• Bank details?
• Social Services records?
Paper Records
• “Relevant Filing System”
• “Temp test”
– could a reasonably competent temporary
worker retrieve the information relating to a
specific individual without leafing through
the file?
Paper Records
• Manual files structured solely in
chronological order are unlikely to be
covered
• Freedom of Information Act will expand
the category of paper records covered
by the Data Protection Act
– Applies to public authorities or bodies
carrying out public functions
– In force from January (probably) 2005
Types Of Data
• Ordinary vs Sensitive Personal Data
• Sensitive Personal Data includes:
– Race/Ethnic origin
– Religion
– Sexual life
– Trade union membership
– Physical or Mental Health
– Commission of offences/criminal
proceedings
– Political opinion
What Is Personal Data?
• Payroll/salary details?
• Internet logs?
• Health records?
• e-mails?
• Electoral register?
• CCTV images?
• Bank details?
• Social Services records?
When Am I Processing
Personal Data?
• Any manipulation of data
• This will include:
– collection
– calling data up on screen
– auditing the information
– storage
– destruction
Who Is Responsible For
Processing?
• Data Controller vs Data Processor
• Data Controller
– Determines the purposes for which the
data are processed and how
– Legally responsible for what happens to
the data
• Data Processor
– Processes data on behalf of/under
instruction of Data Controller
Who Is Responsible For
Processing?
• In a nutshell:
– Do you determine what is done with the
data? (= data controller)
– Do you deal with data under instruction of
third party? (= data processor)
• Internal auditor (=data controller)
• External auditor (=data processor)
• Statutory Auditor (depends)
Who Is Responsible For
Processing?
• Data Controller responsible for
compliance with the Act
• Data Processor is not BUT may be
required to undertake compliance
obligations by contract
– Security/confidentiality
– Only use the data as instructed
• Can be both data controller & processor
Who Is Responsible For
Processing?
• Outsourced functions
– Company to which functions outsourced
likely to be data processor
– Should be a written contract in place
between organisation and company to
which functions outsourced
– Original organisation remains responsible
for compliance
Notification
• Must notify if:
– You are a DATA CONTROLLER and
– process PERSONAL DATA
– on COMPUTER
• Not strictly required if a data processor
for accountancy/audit purposes
• Annual renewal, £35
• 28 days to notify changes
Are We Entitled To
Process The Data?
• Data to be processed fairly & lawfully
• Ordinary Data – unambiguous consent
– actual consent
– necessary to perform a contract
– necessary to decide whether to enter into a
contract
– necessary to comply with a legal obligation
• Sensitive Data – explicit consent
Are We Entitled To
Process The Data?
• Responsibility of the data controller
– If data processor, seek warranty in contract
• Fair processing notice:
– Who will process the data
– What purposes the data will be used for
• is audit included?
– Any further information necessary to be
given for the processing to be fair
• Should notify BEFORE collect data
Are We Entitled To
Process The Data?
• Opt-in, opt-out or neither?
– is it optional?
– is it for marketing purposes?
– does it allow contact by e-mail or SMS?
• “Do not solicit” databases
• Issues of using data collected by third
parties
Are We Entitled To
Process The Data?
• Employee data:
– restrictions on accessing e-mails, call
recordings, CCTV and website logs
• Not only a Data Protection Act issue:
– Human Rights Act; Art 8 ECHR
– Regulation of Investigatory Powers Act
2000
– Telecommunications (Lawful Business
Practice) … Regulations 2000
Are We Entitled To
Process The Data?
• Employee Monitoring and Acceptable
Use Policies:
– for data protection, rely upon “consent” or
“necessary for legitimate interests unless
unwarranted prejudice to data subject”
– for interception, see RIPA & LBP Regs
– see also Data Protection Code, Part 3
• Data processors - seek warranties
What Are The Other Obligations?
• Data to be adequate, relevant and not
excessive
• Data to be accurate and, where
necessary, kept up to date
• Data not to be kept for any longer than
is necessary
• Data controller needs systems for data
management, review and disposal
What Are The Other Obligations?
• Individuals (=data subjects) have rights
of access to personal data
– statutory obligation to reply to requests
– 40 day timetable
– maximum £10 fee
– both electronic and paper records
– beware of identifying other individuals
• Data Controller should have a Subject
Access Procedure
What Are The Other Obligations?
• Appropriate steps to be taken to hold
data securely
– physical and technological measures
– ensure employee reliability
– written contracts with data processors
• Be aware of restrictions on data transfer
to non-EEA countries
– seek consent, “safe harbor” or contract
Are There Any Exemptions?
• Exemption from the eight principles
– e.g. national security; domestic purposes
• Exemption from the non-disclosure
provisions
– e.g. where required by law; to detect crime
• Exemptions from the subject information
provisions
– e.g. regulatory activity; negotiations;
management forecasting and planning
Data Protection And
Freedom Of Information
• For “public authorities” caught by
Freedom of Information Act 2000:
– data protection obligations expanded
– particularly subject access rights
• Publication Schemes
• General “Right to Know”
• January 2005 commencement date
In Summary
Examine the basis for your work:
• are you a data controller or a data
processor?
In Summary
If you are the data controller:
• Appoint a compliance officer
• Have systems in place for data
collection, review and disposal
• Have appropriate contracts with third
party data processors
• Set up standard letters for data requests
In Summary
If you are a data processor:
• Should follow controller’s instructions
• Data controller may propose a written
contract
– their obligation, not yours
– you should seek warranties about data
collection and compliance with the Act
• Do you need a notification?
Any more questions?
Joanne Bone
bonej@irwinmitchell.co.uk
Neil Bentley
bentleyn@irwinmitchell.co.uk
Helen Goldthorpe
goldthorpeh@irwinmitchell.co.uk
0870 1500 100

More Related Content

PPTX
Data protection ppt
PDF
The Data Protection Act What You Need To Know
PPTX
The Data Protection Act
PPTX
Privacy and Data Protection Act 2014 (VIC)
PDF
Privacy and Data Security
PPT
Data Protection Act
PDF
Privacy law-update-whitmeyer-tuffin
PPT
Data Privacy in India and data theft
Data protection ppt
The Data Protection Act What You Need To Know
The Data Protection Act
Privacy and Data Protection Act 2014 (VIC)
Privacy and Data Security
Data Protection Act
Privacy law-update-whitmeyer-tuffin
Data Privacy in India and data theft

What's hot (19)

PPTX
Chapter 08 – Data Protection, Privacy and Freedom of Information - BIT IT5104
PPTX
Presentation on Information Privacy
PPT
Personal privacy and computer technologies
PPT
Merit Event - Understanding and Managing Data Protection
PPTX
Popi act presentation
PPTX
Privacy in simple
PPT
Data Protection (Download for slideshow)
PPT
Privacy and Data Security: Risk Management and Avoidance
PPTX
POPI Seminar FINAL
PPT
“Privacy Today” Slide Presentation
PPSX
POPI Act compliance presentation
PPTX
Information Privacy
PPTX
Data Privacy Introduction
PPTX
Intercity technology - GDPR your training toolkit
PPTX
Protection of Personal Information Bill (POPI)
PPTX
Unit 6 Privacy and Data Protection 8 hr
PDF
What does the GDPR mean for charity communicators? | Scotland Networking Grou...
PDF
Interact 2018 - GDPR for digital publishers, digital agencies and advertisers
PPTX
Balancing Privacy and Digitization
Chapter 08 – Data Protection, Privacy and Freedom of Information - BIT IT5104
Presentation on Information Privacy
Personal privacy and computer technologies
Merit Event - Understanding and Managing Data Protection
Popi act presentation
Privacy in simple
Data Protection (Download for slideshow)
Privacy and Data Security: Risk Management and Avoidance
POPI Seminar FINAL
“Privacy Today” Slide Presentation
POPI Act compliance presentation
Information Privacy
Data Privacy Introduction
Intercity technology - GDPR your training toolkit
Protection of Personal Information Bill (POPI)
Unit 6 Privacy and Data Protection 8 hr
What does the GDPR mean for charity communicators? | Scotland Networking Grou...
Interact 2018 - GDPR for digital publishers, digital agencies and advertisers
Balancing Privacy and Digitization
Ad

Viewers also liked (20)

PDF
Personal data: Legal Issues in Research Data Collection and Sharing by EUDAT ...
PPTX
New Media Internet Expression and European Data Protection
PPTX
Online art galleries
PPTX
Webinar: Compliance and Data Protection in the Big Data Age: MongoDB Security...
PPT
Data Protection Presentation
PDF
Personal Data Protection Act - Employee Data Privacy
PPT
Data protection act
PDF
Data privacy act of 2012 presentation
PPS
Introduction to Data Protection and Information Security
PDF
Data & Privacy: Striking the Right Balance - Jonny Leroy
PPTX
Data Privacy Day Online Reputation Research
PPTX
Amaresa 2 - House Details
PPT
01 speeches stuchery
PDF
Risiko basert testing i praksis
PPTX
PPT
Test audio
PPT
DevsTeam Services | A Trusted Internet Marketing Service Provider
PDF
PPTX
07092014 chapel a encountering god 1
PPTX
CCLBA Data & analytics presentation july 11, 2013
Personal data: Legal Issues in Research Data Collection and Sharing by EUDAT ...
New Media Internet Expression and European Data Protection
Online art galleries
Webinar: Compliance and Data Protection in the Big Data Age: MongoDB Security...
Data Protection Presentation
Personal Data Protection Act - Employee Data Privacy
Data protection act
Data privacy act of 2012 presentation
Introduction to Data Protection and Information Security
Data & Privacy: Striking the Right Balance - Jonny Leroy
Data Privacy Day Online Reputation Research
Amaresa 2 - House Details
01 speeches stuchery
Risiko basert testing i praksis
Test audio
DevsTeam Services | A Trusted Internet Marketing Service Provider
07092014 chapel a encountering god 1
CCLBA Data & analytics presentation july 11, 2013
Ad

Similar to Data Protection and IDEA (20)

PPTX
Data protection
PDF
Protection des données et de la vie privée : nouvelles obligations pour les e...
PPT
Building a register of data processing
PPT
2014 dpa training february nn
PDF
Public sector breakfast club, October 2016, Exeter
PPTX
GDPR: 3 Months On | Guest Speaker: Data Protection Commissioners
PPTX
GDPR Breakfast Briefing for Business Advisors
PDF
mHealth Israel_EU General Data Protection Regulation_Simon Marks
PPTX
Get you and your business GDPR ready
PPTX
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
PDF
GDPR - Sink or Swim
PPTX
GDPR Breakfast Briefing for Business Advisors
PPTX
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
PDF
The principles of the Data Protection Act in detail - uk
PDF
GDPR for your Payroll Bureau
PPTX
Media_644046_smxx (1).pptx
PPT
Dataprotectionactnew13 12-11-111213033116-phpapp02
PDF
Getting Ready for GDPR
PPT
3e - Data Protection
PPT
Data privacy & social media
Data protection
Protection des données et de la vie privée : nouvelles obligations pour les e...
Building a register of data processing
2014 dpa training february nn
Public sector breakfast club, October 2016, Exeter
GDPR: 3 Months On | Guest Speaker: Data Protection Commissioners
GDPR Breakfast Briefing for Business Advisors
mHealth Israel_EU General Data Protection Regulation_Simon Marks
Get you and your business GDPR ready
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
GDPR - Sink or Swim
GDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
The principles of the Data Protection Act in detail - uk
GDPR for your Payroll Bureau
Media_644046_smxx (1).pptx
Dataprotectionactnew13 12-11-111213033116-phpapp02
Getting Ready for GDPR
3e - Data Protection
Data privacy & social media

More from AuditWare Systems Ltd. (14)

PDF
Using IDEA with SAP
PDF
Quick Wins and Shortcuts to Get the Most out of IDEA
PDF
Duplicate Payment Detection using IDEA
PDF
SAP Data and IDEA
PDF
National Fraud Initiative using IDEA
PDF
Using IDEA to Create a Sampling Methodology
PDF
IDEA to Detect Duplicate Invoice Payments
PDF
Smart analyzer v9 product profile
PDF
Space brochure
PDF
Case ware monitor product profile
PDF
Idea v9 product profile
PPT
Benford's Law - Example - EDF
PPT
Extracting data from IDEA
PDF
Applications of IDEA - payroll
Using IDEA with SAP
Quick Wins and Shortcuts to Get the Most out of IDEA
Duplicate Payment Detection using IDEA
SAP Data and IDEA
National Fraud Initiative using IDEA
Using IDEA to Create a Sampling Methodology
IDEA to Detect Duplicate Invoice Payments
Smart analyzer v9 product profile
Space brochure
Case ware monitor product profile
Idea v9 product profile
Benford's Law - Example - EDF
Extracting data from IDEA
Applications of IDEA - payroll

Recently uploaded (20)

PDF
Buy Verified Stripe Accounts for Sale - Secure and.pdf
PDF
discourse-2025-02-building-a-trillion-dollar-dream.pdf
PDF
Lecture1.pdf buss1040 uses economics introduction
PDF
Principal of magaement is good fundamentals in economics
PPTX
FL INTRODUCTION TO AGRIBUSINESS CHAPTER 1
PDF
THE EFFECT OF FOREIGN AID ON ECONOMIC GROWTH IN ETHIOPIA
PPTX
PPT-Lesson-2-Recognize-a-Potential-Market-2-3.pptx
PDF
How to join illuminati agent in Uganda Kampala call 0782561496/0756664682
PDF
1a In Search of the Numbers ssrn 1488130 Oct 2009.pdf
PDF
USS pension Report and Accounts 2025.pdf
PPTX
2. RBI.pptx202029291023i38039013i92292992
PDF
Fintech Regulatory Sandbox: Lessons Learned and Future Prospects
PDF
Pitch Deck.pdf .pdf all about finance in
PPTX
introuction to banking- Types of Payment Methods
PDF
6a Transition Through Old Age in a Dynamic Retirement Distribution Model JFP ...
PDF
The Right Social Media Strategy Can Transform Your Business
PDF
Bitcoin Layer August 2025: Power Laws of Bitcoin: The Core and Bubbles
PDF
HCWM AND HAI FOR BHCM STUDENTS(1).Pdf and ptts
PDF
NAPF_RESPONSE_TO_THE_PENSIONS_COMMISSION_8 _2_.pdf
PPT
features and equilibrium under MONOPOLY 17.11.20.ppt
Buy Verified Stripe Accounts for Sale - Secure and.pdf
discourse-2025-02-building-a-trillion-dollar-dream.pdf
Lecture1.pdf buss1040 uses economics introduction
Principal of magaement is good fundamentals in economics
FL INTRODUCTION TO AGRIBUSINESS CHAPTER 1
THE EFFECT OF FOREIGN AID ON ECONOMIC GROWTH IN ETHIOPIA
PPT-Lesson-2-Recognize-a-Potential-Market-2-3.pptx
How to join illuminati agent in Uganda Kampala call 0782561496/0756664682
1a In Search of the Numbers ssrn 1488130 Oct 2009.pdf
USS pension Report and Accounts 2025.pdf
2. RBI.pptx202029291023i38039013i92292992
Fintech Regulatory Sandbox: Lessons Learned and Future Prospects
Pitch Deck.pdf .pdf all about finance in
introuction to banking- Types of Payment Methods
6a Transition Through Old Age in a Dynamic Retirement Distribution Model JFP ...
The Right Social Media Strategy Can Transform Your Business
Bitcoin Layer August 2025: Power Laws of Bitcoin: The Core and Bubbles
HCWM AND HAI FOR BHCM STUDENTS(1).Pdf and ptts
NAPF_RESPONSE_TO_THE_PENSIONS_COMMISSION_8 _2_.pdf
features and equilibrium under MONOPOLY 17.11.20.ppt

Data Protection and IDEA

  • 1. Data Protection and IDEA Joanne Bone & Neil Bentley Irwin Mitchell 11 May 2004
  • 2. Why Is Data Protection Important? • Data Protection Act 1998 • Overseen by the UK’s Information Commissioner • Potential Civil and Criminal Liability
  • 3. Why Is Data Protection Important? • Criminal Liability • Fines for breach – Up to £5000 in Magistrates’ Court – Unlimited in Crown Court • Company officers, directors and managers can be personally liable
  • 4. Why Is Data Protection Important? • Civil Liability • Any breach of the Act is actionable • Compensation for damage and/or distress • In practice Courts are awarding damages for breach of the Act
  • 5. So When Does The Data Protection Act Apply? • The Act applies to the PROCESSING of PERSONAL DATA
  • 6. What Is Personal Data? • Personal data can be any information which relates to a living individual who is identifiable from that data alone or in conjunction with other data • Both paper and electronic records can be covered
  • 7. What Is Personal Data? • Durant v Financial Services Authority • Definition of personal data interpreted by the Court in a more restrictive way • Information now only personal data where it affects the individual’s privacy – Is the information biographical? – Is the information focused on the individual?
  • 8. What Is Personal Data? • Payroll/salary details? • Internet logs? • Health records? • e-mails? • Electoral register? • CCTV images? • Bank details? • Social Services records?
  • 9. Paper Records • “Relevant Filing System” • “Temp test” – could a reasonably competent temporary worker retrieve the information relating to a specific individual without leafing through the file?
  • 10. Paper Records • Manual files structured solely in chronological order are unlikely to be covered • Freedom of Information Act will expand the category of paper records covered by the Data Protection Act – Applies to public authorities or bodies carrying out public functions – In force from January (probably) 2005
  • 11. Types Of Data • Ordinary vs Sensitive Personal Data • Sensitive Personal Data includes: – Race/Ethnic origin – Religion – Sexual life – Trade union membership – Physical or Mental Health – Commission of offences/criminal proceedings – Political opinion
  • 12. What Is Personal Data? • Payroll/salary details? • Internet logs? • Health records? • e-mails? • Electoral register? • CCTV images? • Bank details? • Social Services records?
  • 13. When Am I Processing Personal Data? • Any manipulation of data • This will include: – collection – calling data up on screen – auditing the information – storage – destruction
  • 14. Who Is Responsible For Processing? • Data Controller vs Data Processor • Data Controller – Determines the purposes for which the data are processed and how – Legally responsible for what happens to the data • Data Processor – Processes data on behalf of/under instruction of Data Controller
  • 15. Who Is Responsible For Processing? • In a nutshell: – Do you determine what is done with the data? (= data controller) – Do you deal with data under instruction of third party? (= data processor) • Internal auditor (=data controller) • External auditor (=data processor) • Statutory Auditor (depends)
  • 16. Who Is Responsible For Processing? • Data Controller responsible for compliance with the Act • Data Processor is not BUT may be required to undertake compliance obligations by contract – Security/confidentiality – Only use the data as instructed • Can be both data controller & processor
  • 17. Who Is Responsible For Processing? • Outsourced functions – Company to which functions outsourced likely to be data processor – Should be a written contract in place between organisation and company to which functions outsourced – Original organisation remains responsible for compliance
  • 18. Notification • Must notify if: – You are a DATA CONTROLLER and – process PERSONAL DATA – on COMPUTER • Not strictly required if a data processor for accountancy/audit purposes • Annual renewal, £35 • 28 days to notify changes
  • 19. Are We Entitled To Process The Data? • Data to be processed fairly & lawfully • Ordinary Data – unambiguous consent – actual consent – necessary to perform a contract – necessary to decide whether to enter into a contract – necessary to comply with a legal obligation • Sensitive Data – explicit consent
  • 20. Are We Entitled To Process The Data? • Responsibility of the data controller – If data processor, seek warranty in contract • Fair processing notice: – Who will process the data – What purposes the data will be used for • is audit included? – Any further information necessary to be given for the processing to be fair • Should notify BEFORE collect data
  • 21. Are We Entitled To Process The Data? • Opt-in, opt-out or neither? – is it optional? – is it for marketing purposes? – does it allow contact by e-mail or SMS? • “Do not solicit” databases • Issues of using data collected by third parties
  • 22. Are We Entitled To Process The Data? • Employee data: – restrictions on accessing e-mails, call recordings, CCTV and website logs • Not only a Data Protection Act issue: – Human Rights Act; Art 8 ECHR – Regulation of Investigatory Powers Act 2000 – Telecommunications (Lawful Business Practice) … Regulations 2000
  • 23. Are We Entitled To Process The Data? • Employee Monitoring and Acceptable Use Policies: – for data protection, rely upon “consent” or “necessary for legitimate interests unless unwarranted prejudice to data subject” – for interception, see RIPA & LBP Regs – see also Data Protection Code, Part 3 • Data processors - seek warranties
  • 24. What Are The Other Obligations? • Data to be adequate, relevant and not excessive • Data to be accurate and, where necessary, kept up to date • Data not to be kept for any longer than is necessary • Data controller needs systems for data management, review and disposal
  • 25. What Are The Other Obligations? • Individuals (=data subjects) have rights of access to personal data – statutory obligation to reply to requests – 40 day timetable – maximum £10 fee – both electronic and paper records – beware of identifying other individuals • Data Controller should have a Subject Access Procedure
  • 26. What Are The Other Obligations? • Appropriate steps to be taken to hold data securely – physical and technological measures – ensure employee reliability – written contracts with data processors • Be aware of restrictions on data transfer to non-EEA countries – seek consent, “safe harbor” or contract
  • 27. Are There Any Exemptions? • Exemption from the eight principles – e.g. national security; domestic purposes • Exemption from the non-disclosure provisions – e.g. where required by law; to detect crime • Exemptions from the subject information provisions – e.g. regulatory activity; negotiations; management forecasting and planning
  • 28. Data Protection And Freedom Of Information • For “public authorities” caught by Freedom of Information Act 2000: – data protection obligations expanded – particularly subject access rights • Publication Schemes • General “Right to Know” • January 2005 commencement date
  • 29. In Summary Examine the basis for your work: • are you a data controller or a data processor?
  • 30. In Summary If you are the data controller: • Appoint a compliance officer • Have systems in place for data collection, review and disposal • Have appropriate contracts with third party data processors • Set up standard letters for data requests
  • 31. In Summary If you are a data processor: • Should follow controller’s instructions • Data controller may propose a written contract – their obligation, not yours – you should seek warranties about data collection and compliance with the Act • Do you need a notification?
  • 32. Any more questions? Joanne Bone bonej@irwinmitchell.co.uk Neil Bentley bentleyn@irwinmitchell.co.uk Helen Goldthorpe goldthorpeh@irwinmitchell.co.uk 0870 1500 100