Ayrshire LETs complies with data protection legislation
The eight principles
The Data Protection Act 1998 sets out eight rules that data controllers must follow for protecting personal information - these are known as the eight principles.
Personal data must be:
- processed fairly and lawfully
- processed only for one or more specified and lawful purpose
- adequate, relevant and not excessive for those purposes
- accurate and kept up to date - data subjects have the right to have inaccurate personal data corrected or destroyed if the personal information is inaccurate to any matter of fact
- kept for no longer than is necessary for the purposes it is being processed
- processed in line with the rights of individuals - this includes the right to be informed of all the information held about them, to prevent processing of their personal information for marketing purposes, and to compensation if they can prove they have been damaged by a data controller's non-compliance with the Act
- secured against accidental loss, destruction or damage and against unauthorised or unlawful processing - this applies to you even if your business uses a third party to process personal information on your behalf
- not transferred to countries outside the European Economic Area - the EU plus Norway, Iceland and Liechtenstein - that do not have adequate protection for individual's personal information, unless a condition from Schedule four of the Act can be met
If a data controller's processing of personal information does not comply with the principles, the Information Commissioner can take enforcement action against that data controller.
This summary of the Data Protection Act 1998 taken from: http://www.businesslink.gov.uk/bdotg/action/layer?topicId=1074448560&tc=000KW022006782
