We all have data that is personal to us and some that are even sensitive. We expect government bodies, authorities and businesses that process our data to do so responsibly.
The law also expects this, and there are legal requirements surrounding the use of everyone’s personal data. Therefore, if you or your business processes personal data, you must follow strict rules to ensure you comply with data protection laws.
Data security incidents are not uncommon. According to the Information Commissioner’s Office (ICO) latest statistics on data security incident trends:
You or your business must take care to avoid personal data breaches. You can do this by understanding the rules regarding personal data. You must also know what your legal responsibilities are under the Data Protection Act 2018 and UK GDPR.
This article will look at the Data Protection Act 2018 and what businesses need to do by law. It will also cover breaches of the Act and the rights of individuals when it comes to their data.
The Data Protection Act 2018 (DPA 2018) is a UK Act of Parliament. The DPA 2018 superseded the Data Protection Act 1998 on 23 rd May 2018 when the EU General Data Protection Regulation (GDPR) 2016 came into force. The GDPR 2016 is an EU regulation on data protection and privacy in the European Union (EU) and the European Economic Area (EEA).
As the UK was a previous member state, the EU GDPR was directly applicable. After the UK left the EU, the GDPR was retained in domestic law and became the UK General Data Protection Regulation (UK GDPR) on 1 st January 2021. The UK GDPR sits alongside an amended version of the Data Protection Act 2018, and both apply to the protection of personal data. Even though these laws complement one another, businesses must comply with both, as there are differences.
If you do any business in or with countries in Europe, you may have to comply with both EU GDPR and UK GDPR. If in doubt, it is always best to seek legal advice to ensure you are correctly complying with the law.
Data protection legislation controls how people’s personal information is used by organisations, businesses or the government. It also introduces ‘digital rights’ for individual citizens, as personal information is increasingly stored in computer databases. It also determines how, when and why any organisation can process personal data.
Article 5 of the UK GDPR sets out seven key principles, which lie at the heart of the general data protection regime (ICO). These principles are:
1. Lawfulness, fairness and transparency – Personal data must be processed lawfully, fairly and in a transparent manner.
2. Purpose limitation – Personal data can only be collected for specified, explicit and legitimate purposes. It can only be used for a specific purpose and no other. Individual’s details must not be passed onto third parties unless they have already consented.
3. Data minimisation – No more than the minimum amount of data should be kept for specific processing.
4. Accuracy – Data must be accurate and where necessary kept up to date. If the data held is wrong or out of date, individuals have the right to have it corrected or deleted.
5. Storage limitation – Data that is no longer required should be removed.
6. Integrity and confidentiality (security) – Data must be processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and accidental loss, destruction or damage.
7. Accountability – The controller has responsibility for demonstrating compliance with the other principles.
There are also principles in Part 3 of the DPA 2018 for law enforcement processing.
These principles are a vital part of ensuring businesses remain compliant with data protection laws. If you do not comply with these principles, it can result in substantial fines.
According to the Information Commissioner’s Office (ICO), data protection is:
“The fair and proper use of information about people. It’s part of the fundamental right to privacy – but on a more practical level, it’s really about building trust between people and organisations. It’s about treating people fairly and openly, recognising their right to have control over their own identity and their interactions with others, and striking a balance with the wider interests of society.”
Therefore, the DPA 2018 aims to:
All businesses and individuals who process any personal data must comply with the DPA 2018 and UK GDPR.
Processing can mean anything done with data, such as (this list is not exhaustive):
Data protection laws will apply if you or your business carry out any of the above activities and have any information about individuals for any business or other non-household purpose. It does not matter the size of your business, turnover or nature. If you process any personal data, you must comply with the law.
Under the DPA 2018, you must also register and pay a data protection fee to the ICO unless you can show that you are exempt. If you are not exempt and fail to register, you could face a fine. You can use the ICO’s self-assessment tool to determine whether you need to register.
Personal data is information that relates to an identified or identifiable person (a data subject) who could be directly or indirectly identified based on the information.
It includes an individual’s:
There are also special categories of personal data, which covers sensitive information, for example:
Sensitive information has stronger legal protection. There must be lawful grounds for processing these data types, and additional safeguards must be in place. There are separate safeguards for personal data relating to criminal convictions and offences.
The DPA 2018 and UK GDPR apply to electronic files and paper filing systems that include personally identifiable information. Spoken information is not included, but confidentiality can be breached if personal or sensitive information is discussed where others can overhear.
As a business owner, you have overall responsibility for protecting people’s personal data.
There are also specific responsibilities detailed in data protection laws, for example:
Everyone in your business will have some responsibilities regarding data protection. If you are an employer, you must also make your employees aware of their rights concerning their own personal data and what they must do to protect other peoples.
Information on the responsibilities of controllers and processors is available on the official ICO website.
The Information Commissioner’s Office (ICO) is the regulator for data protection in the UK. According to the ICO, a personal data breach is:
“A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. This includes breaches that are the result of both accidental and deliberate causes. It also means that a breach is more than just about losing personal data. A personal data breach can be broadly defined as a security incident that has affected the confidentiality, integrity or availability of personal data.”
Some examples of data breaches are:
Many would think that the majority of data breaches come from cyber-security incidents, such as database hacking. However, they often result from businesses lacking appropriate procedures or training in personal data handling.
You can find examples of breaches on the official ICO website.
Where possible, you should prevent personal data breaches. However, sometimes it is not always possible as errors can and do happen. If you become aware of a personal data breach, you must:
There should be procedures in place for identifying, reporting and investigating personal data breaches.
Having robust procedures and response plans will help you deal with any incidents in an organised manner and assist in making decisions about reporting. If you have employees, you should make it clear what a personal data breach is and what their roles and responsibilities are.
Further information on handling personal data breaches can be found on the ICO website.
If you receive a complaint from someone who believes their data has been misused or has not been kept secure, you should:
It is important to have procedures in place for handling complaints involving personal data.
If an individual is not happy with how their complaint has been handled, they can contact the ICO who may decide to investigate their claim.
If there has been a breach, enforcement action can be taken against the business, for example:
Individuals who have been affected by the breach may also take a case to court under data protection laws. They can enforce their rights if they think they have been breached or claim compensation for any damage or distress caused (or both).
Non-compliance with the law can be costly for businesses. It can have serious consequences for business operations and could even result in closure.
Individuals have rights, under the DPA 2018, to know what information businesses are storing about them.
They have a right to:
They also have rights when an organisation is using their personal data for:
You must ensure that you, and anyone who works for you, are familiar with individuals’ rights concerning their personal data.
If you or your business receives a request from an individual asking for access or erasure of their data, you must:
You are permitted to charge administrative costs for requests in particular situations, e.g. where there is a request for a large amount of information, or it would take a significant amount of time to process.
You can find out more about individuals’ rights.
Data protection laws are there to keep our personal data safe and so that businesses respect our privacy. People need to trust that companies are processing their data responsibly and are complying with the law.
As an individual, you will also have personal data processed by many different organisations. You would expect these companies to handle your data safely and legally. If you or your business processes any personal data, you should treat it how you would expect your own to be treated. There is not only a legal obligation but a moral one.
It is easy for businesses, particularly smaller ones, to slip up regarding data protection. Understanding what you need to do will help prevent costly mistakes. It is always best to seek professional advice if you are unsure of the rules and your legal obligations.