SlideShare a Scribd company logo
NOTIFICATION BY DATA
    CONTROLLERS

1                  Vishnu Kesarwani (IMS2007011)
                    Rajendra Prasad (IMS2007012)
                                     2nd Semester
            MS (Cyber Law & Information Security)
                                  IIIT-Allahabad
INTRODUCTION
   The Data Protection Act, 1984 established the Data
    Protection Register and the system of registration
    maintained by the Registrar.

   The Data Protection Act, 1998 introduced a new system of
    notification which replaced the registration scheme.

Meaning:
 Notification is the process by which a data controller
  informs the Commissioner of certain details about the
  processing of personal data carried out by that data
  controller.


                                                               2
CONTD…


Purpose
 Transparency or openness



Interest
Notification fulfils the interests of :
 Data controllers

 Data subjects



                                          3
NOTIFICATION EXEMPTIONS
The Act provides exemption from notification for data
  controllers.

Exemptions are :

   data controllers who only process personal data for :
     staff administration
     advertising, marketing and public relations (of their
      own business)
     accounts and records


   not for profit Organisations

                                                              4
CONTD….

   processing personal data for personal, family or household
    affairs

   data controllers who only process personal data for the
    maintenance of a public register

   data controllers who do not process personal data on
    computer




                                                                 5
STAFF ADMINISTRATION EXEMPTION
The processing is for the purposes of

        appointments or
        removals,
        pay,
        discipline,
        superannuation,
        work management or
        other personnel matters in relation to the staff of the data controller;

   (b) is of personal data in respect of which the data subject is -

     o a past,
     o existing or
     o prospective
     member of staff of the data controller


   (c) is of personal data consisting of the name, address and other identifiers of
    the data subject or information as to -
        qualifications,                                                               6
     o   work experience or
     o   pay
ADVERTISING, MARKETING AND PUBLIC
RELATIONS EXEMPTION

   (a) is for the purposes of
       advertising or
       marketing the data controller's business,
       activity,
       goods or services
       and promoting public relations in connection with that
        business or activity, or those goods or services;

   (b) is of personal data in respect of which the data subject is -
    o   a past,
    o   existing or
    o   prospective customer or supplier




                                                                        7
ACCOUNTS AND RECORDS EXEMPTION
The processing –

   (a) is for the purposes of
     keeping accounts relating to any business or
     other activity carried on by the data controller, or any person
      as a customer or supplier, or
     keeping records of purchases, sales or


   (b) is of personal data in respect of which the data subject is -

    o   a past,
    o   existing or
    o   prospective customer or
    o   supplier

                                                                        8
NON PROFIT-MAKING ORGANISATIONS
EXEMPTIONS

The processing -

   (a) is carried out by a data controller which is a body or association
    which is not established or conducted for profit;

   (b) is for the purposes of establishing or maintaining membership of
    or support for the body or association, or providing or administering
    activities for individuals who are either members of the body or
    association or have regular contact with it;

   (c) is of personal data in respect of which the data subject is -

        a past,
        existing or
        prospective member of the body or organisation;


                                                                             9
THE REGISTRABLE PARTICULARS
According to Section 16(1) the registrable particulars means:

   Data Controller’s name and address,

   The name and address of the representative,

   A description of the personal data,

   A description of the purpose or purposes,

   A description of any recipient or recipients,

   The names, or a description of, any countries or territories outside the
    European economic area,


                                                                               10
Duty of the data controller
Duty to notify changes
 If any changes takes place regarding personal data then
  data controller is bound by the Act to notify the
  Commissioner.

Duty to make certain information available
 The data controller has not notified the relevant
  particulars in respect of that processing under section 18,
  the data controller must, within twenty-one days of
  receiving a written request from any person, make the
  relevant particulars available to that person in writing free
  of charge.
                                                                  11
Function of the Commissioner

   As soon as practicable after the passing of this Act, the
    Commissioner shall submit to the Secretary of State
    proposals as to the provisions to be included in the first
    notification regulations.

   The Commissioner shall keep under review the working of
    notification regulations and may from time to time submit
    to the Secretary of State proposals as to amendments to be
    made to the regulations.




                                                                 12
Function of the secretary of state
   The Secretary of State may from time to time require the
    Commissioner to consider any matter relating to
    notification regulations and to submit to him proposals as
    to amendments to be made to the regulations in connection
    with that matter.

   Before making any notification regulations, the Secretary
    of State shall—
      (a) consider any proposals made to him by the
        Commissioner under subsection (1), (2) or (3), and
      (b) consult the Commissioner
   Power to make provision for appointment of data protection
    supervisors

                                                                 13
Offences relating to notification
  It is an offence to process personal data without notification unless:-

     the personal data fall within either of the national security or
      domestic purposes exemptions,

     the personal data are exempt under the transitional exemptions,

     the personal data fall within the ―relevant filing system‖/
      ―accessible record‖ or public register exceptions referred to above,

     the processing operation falls within the exemptions referred to in
      the Regulations

     the processing is of a description which notification regulations
      provide is exempt from the requirements to notify on the ground
      that it is unlikely to prejudice the rights and freedoms of data
                                                                             14
      subjects. No such provision was included in the Regulations.
CONTD…

   It will also be an offence for a person to fail to notify the
    Commissioner of changes to the register entry.

   The Regulations provided that such notification must be
    given as soon as practicable and in any event within a
    period of 28 days from the date upon which the entry
    becomes inaccurate or incomplete.

   Defense: due diligence


                                                                    15
Nature of Offence

   When Data Controller fail to comply the provision of the
    Act or contravene the provision then the Data Controller
    will be held liable.

   The nature of offence will be criminal.

   In all cases the Data Controller will be held strictly liable (
    strict liability offence).




                                                                      16
REFERENCES




                                                                             1/28/2010
 THE DATA PROTECTION ACT, 1998

 Data Protection Act 1998: Legal Guidance; available from
  http://www.ico.gov.uk/upload/documents/library/data_protection/detailed
  _specialist_guides/data_protection_act_legal_guidance.pdf
 Hamilton, Angus and Jay, Rosemary, Data Protection Act 1998 (UK:
  Sweet & Maxwell, 1999)




                                                                            17
THANKS


         18

More Related Content

PDF
GDPR - The new era of data protection
PDF
LSA19: What Europe Can Teach U.S. Companies About Location and Data Privacy W...
PDF
Third Principle Of The Data Protection Act, 1998 (Uk)
PDF
LOPD - Spanish ethical and legal issues in the context of an international IC...
PPT
Challenges to Achieve Privacy for Online Consumers in Mexico
PDF
Judgment of the Court_ the right to be forgotten
PDF
10 Things You Need To Know About Privacy
PDF
20180305 the dayafter_bavovdh_cranium_dpo_pro
GDPR - The new era of data protection
LSA19: What Europe Can Teach U.S. Companies About Location and Data Privacy W...
Third Principle Of The Data Protection Act, 1998 (Uk)
LOPD - Spanish ethical and legal issues in the context of an international IC...
Challenges to Achieve Privacy for Online Consumers in Mexico
Judgment of the Court_ the right to be forgotten
10 Things You Need To Know About Privacy
20180305 the dayafter_bavovdh_cranium_dpo_pro

What's hot (20)

PPTX
Data protection compliance projects
PDF
Saying "I Don't": the requirement of data subject consent for purposes of dat...
PDF
GDPR infographic
DOCX
The implementation of gdpr in greece (1)
PDF
EFA Skillshare - Jitty van Doodewaerd
PPT
Ubicomp challenges for privacy law
PPTX
GDPR: The Catalyst for Customer 360
DOCX
General data protection regulation - European union
PPT
Data Protection Act
PPTX
Security and Privacy in Deals (altheim & mahajan)(6-3 -2015)
PPTX
Presentation on GDPR
PDF
Federal Data Protection Act (FDPA)
PDF
Practical steps to take in preparation for the Protection of Personal Informa...
PPTX
20131009 aon security breach legislation
PPTX
Draft Bill on the Protection of Personal Data
PPTX
Things to know about GDPR in 2018
PDF
Put your left leg in, put your left leg out: the exclusions and exemptions of...
PDF
Quick guide gdpr
PPTX
The General Data Protection Regulation ("GDPR")
PDF
Regulation (EU) 2016_679_GDPR_Overview_June 2016
Data protection compliance projects
Saying "I Don't": the requirement of data subject consent for purposes of dat...
GDPR infographic
The implementation of gdpr in greece (1)
EFA Skillshare - Jitty van Doodewaerd
Ubicomp challenges for privacy law
GDPR: The Catalyst for Customer 360
General data protection regulation - European union
Data Protection Act
Security and Privacy in Deals (altheim & mahajan)(6-3 -2015)
Presentation on GDPR
Federal Data Protection Act (FDPA)
Practical steps to take in preparation for the Protection of Personal Informa...
20131009 aon security breach legislation
Draft Bill on the Protection of Personal Data
Things to know about GDPR in 2018
Put your left leg in, put your left leg out: the exclusions and exemptions of...
Quick guide gdpr
The General Data Protection Regulation ("GDPR")
Regulation (EU) 2016_679_GDPR_Overview_June 2016
Ad

Similar to Notification By Data Controllers Under The Data Protection Act, 1998 (Uk) (20)

PPT
3e - Data Protection
PDF
The principles of the Data Protection Act in detail - uk
PPT
Dataprotectionactnew13 12-11-111213033116-phpapp02
PPT
Data protection act new 13 12-11
PPTX
Data protection
PPT
Merit Event - Understanding and Managing Data Protection
PDF
Administrative and public law seminar
PPTX
Chapter 08 – Data Protection, Privacy and Freedom of Information - BIT IT5104
PDF
Data Protection Seminar_GDPR_ISOLAS_26-06-17
PPT
Data Protection Act
PPT
Data Protection Act
PPTX
3A – DATA PROTECTION: ADVICE
 
PPT
Gary Davis
PPT
Safety And Security Of Data 4
PPTX
Changing legislation – General Data Protection Regulation (GDPR) and librarie...
PPTX
The General Data Protection Regulation (GDPR) in Ireland-What You Should Know
PDF
The Data Protection Act What You Need To Know
PPTX
The Data Protection Act
PPT
Data protection
PDF
Data Protection Act 1998 (amended 2000)
3e - Data Protection
The principles of the Data Protection Act in detail - uk
Dataprotectionactnew13 12-11-111213033116-phpapp02
Data protection act new 13 12-11
Data protection
Merit Event - Understanding and Managing Data Protection
Administrative and public law seminar
Chapter 08 – Data Protection, Privacy and Freedom of Information - BIT IT5104
Data Protection Seminar_GDPR_ISOLAS_26-06-17
Data Protection Act
Data Protection Act
3A – DATA PROTECTION: ADVICE
 
Gary Davis
Safety And Security Of Data 4
Changing legislation – General Data Protection Regulation (GDPR) and librarie...
The General Data Protection Regulation (GDPR) in Ireland-What You Should Know
The Data Protection Act What You Need To Know
The Data Protection Act
Data protection
Data Protection Act 1998 (amended 2000)
Ad

Recently uploaded (20)

PDF
Per capita expenditure prediction using model stacking based on satellite ima...
PDF
Approach and Philosophy of On baking technology
PDF
Encapsulation theory and applications.pdf
PDF
CIFDAQ's Market Insight: SEC Turns Pro Crypto
PPTX
MYSQL Presentation for SQL database connectivity
PDF
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
PDF
Machine learning based COVID-19 study performance prediction
PPT
“AI and Expert System Decision Support & Business Intelligence Systems”
PDF
Network Security Unit 5.pdf for BCA BBA.
PDF
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
PDF
Electronic commerce courselecture one. Pdf
PPTX
Understanding_Digital_Forensics_Presentation.pptx
PDF
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
PPT
Teaching material agriculture food technology
PPTX
A Presentation on Artificial Intelligence
PDF
Spectral efficient network and resource selection model in 5G networks
PDF
The Rise and Fall of 3GPP – Time for a Sabbatical?
PDF
Review of recent advances in non-invasive hemoglobin estimation
PDF
Unlocking AI with Model Context Protocol (MCP)
PDF
Building Integrated photovoltaic BIPV_UPV.pdf
Per capita expenditure prediction using model stacking based on satellite ima...
Approach and Philosophy of On baking technology
Encapsulation theory and applications.pdf
CIFDAQ's Market Insight: SEC Turns Pro Crypto
MYSQL Presentation for SQL database connectivity
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
Machine learning based COVID-19 study performance prediction
“AI and Expert System Decision Support & Business Intelligence Systems”
Network Security Unit 5.pdf for BCA BBA.
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
Electronic commerce courselecture one. Pdf
Understanding_Digital_Forensics_Presentation.pptx
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
Teaching material agriculture food technology
A Presentation on Artificial Intelligence
Spectral efficient network and resource selection model in 5G networks
The Rise and Fall of 3GPP – Time for a Sabbatical?
Review of recent advances in non-invasive hemoglobin estimation
Unlocking AI with Model Context Protocol (MCP)
Building Integrated photovoltaic BIPV_UPV.pdf

Notification By Data Controllers Under The Data Protection Act, 1998 (Uk)

  • 1. NOTIFICATION BY DATA CONTROLLERS 1 Vishnu Kesarwani (IMS2007011) Rajendra Prasad (IMS2007012) 2nd Semester MS (Cyber Law & Information Security) IIIT-Allahabad
  • 2. INTRODUCTION  The Data Protection Act, 1984 established the Data Protection Register and the system of registration maintained by the Registrar.  The Data Protection Act, 1998 introduced a new system of notification which replaced the registration scheme. Meaning:  Notification is the process by which a data controller informs the Commissioner of certain details about the processing of personal data carried out by that data controller. 2
  • 3. CONTD… Purpose  Transparency or openness Interest Notification fulfils the interests of :  Data controllers  Data subjects 3
  • 4. NOTIFICATION EXEMPTIONS The Act provides exemption from notification for data controllers. Exemptions are :  data controllers who only process personal data for :  staff administration  advertising, marketing and public relations (of their own business)  accounts and records  not for profit Organisations 4
  • 5. CONTD….  processing personal data for personal, family or household affairs  data controllers who only process personal data for the maintenance of a public register  data controllers who do not process personal data on computer 5
  • 6. STAFF ADMINISTRATION EXEMPTION The processing is for the purposes of  appointments or  removals,  pay,  discipline,  superannuation,  work management or  other personnel matters in relation to the staff of the data controller;  (b) is of personal data in respect of which the data subject is - o a past, o existing or o prospective member of staff of the data controller  (c) is of personal data consisting of the name, address and other identifiers of the data subject or information as to -  qualifications, 6 o work experience or o pay
  • 7. ADVERTISING, MARKETING AND PUBLIC RELATIONS EXEMPTION  (a) is for the purposes of  advertising or  marketing the data controller's business,  activity,  goods or services  and promoting public relations in connection with that business or activity, or those goods or services;  (b) is of personal data in respect of which the data subject is - o a past, o existing or o prospective customer or supplier 7
  • 8. ACCOUNTS AND RECORDS EXEMPTION The processing –  (a) is for the purposes of  keeping accounts relating to any business or  other activity carried on by the data controller, or any person as a customer or supplier, or  keeping records of purchases, sales or  (b) is of personal data in respect of which the data subject is - o a past, o existing or o prospective customer or o supplier 8
  • 9. NON PROFIT-MAKING ORGANISATIONS EXEMPTIONS The processing -  (a) is carried out by a data controller which is a body or association which is not established or conducted for profit;  (b) is for the purposes of establishing or maintaining membership of or support for the body or association, or providing or administering activities for individuals who are either members of the body or association or have regular contact with it;  (c) is of personal data in respect of which the data subject is -  a past,  existing or  prospective member of the body or organisation; 9
  • 10. THE REGISTRABLE PARTICULARS According to Section 16(1) the registrable particulars means:  Data Controller’s name and address,  The name and address of the representative,  A description of the personal data,  A description of the purpose or purposes,  A description of any recipient or recipients,  The names, or a description of, any countries or territories outside the European economic area, 10
  • 11. Duty of the data controller Duty to notify changes  If any changes takes place regarding personal data then data controller is bound by the Act to notify the Commissioner. Duty to make certain information available  The data controller has not notified the relevant particulars in respect of that processing under section 18, the data controller must, within twenty-one days of receiving a written request from any person, make the relevant particulars available to that person in writing free of charge. 11
  • 12. Function of the Commissioner  As soon as practicable after the passing of this Act, the Commissioner shall submit to the Secretary of State proposals as to the provisions to be included in the first notification regulations.  The Commissioner shall keep under review the working of notification regulations and may from time to time submit to the Secretary of State proposals as to amendments to be made to the regulations. 12
  • 13. Function of the secretary of state  The Secretary of State may from time to time require the Commissioner to consider any matter relating to notification regulations and to submit to him proposals as to amendments to be made to the regulations in connection with that matter.  Before making any notification regulations, the Secretary of State shall—  (a) consider any proposals made to him by the Commissioner under subsection (1), (2) or (3), and  (b) consult the Commissioner  Power to make provision for appointment of data protection supervisors 13
  • 14. Offences relating to notification It is an offence to process personal data without notification unless:-  the personal data fall within either of the national security or domestic purposes exemptions,  the personal data are exempt under the transitional exemptions,  the personal data fall within the ―relevant filing system‖/ ―accessible record‖ or public register exceptions referred to above,  the processing operation falls within the exemptions referred to in the Regulations  the processing is of a description which notification regulations provide is exempt from the requirements to notify on the ground that it is unlikely to prejudice the rights and freedoms of data 14 subjects. No such provision was included in the Regulations.
  • 15. CONTD…  It will also be an offence for a person to fail to notify the Commissioner of changes to the register entry.  The Regulations provided that such notification must be given as soon as practicable and in any event within a period of 28 days from the date upon which the entry becomes inaccurate or incomplete.  Defense: due diligence 15
  • 16. Nature of Offence  When Data Controller fail to comply the provision of the Act or contravene the provision then the Data Controller will be held liable.  The nature of offence will be criminal.  In all cases the Data Controller will be held strictly liable ( strict liability offence). 16
  • 17. REFERENCES 1/28/2010  THE DATA PROTECTION ACT, 1998  Data Protection Act 1998: Legal Guidance; available from http://www.ico.gov.uk/upload/documents/library/data_protection/detailed _specialist_guides/data_protection_act_legal_guidance.pdf  Hamilton, Angus and Jay, Rosemary, Data Protection Act 1998 (UK: Sweet & Maxwell, 1999) 17
  • 18. THANKS 18