All of these pieces of information count as personal information for the purposes of data protection, and within the EU, must be subject to special handling to keep them safe. This post will concentrate on the EU requirements because a) they're something I know a bit about and b) they're stricter than everyone else's. They are good principles to use, even if you're not legally required - and people within the EU are - to follow them.
In the UK, the relevant legislation is the Data Protection Act 1998, implementing a European Directive, and the person given powers of enforcement for that act is the Information Commissioner. S/He formally notifies companies that they are in breach of the law, can prosecute criminal misuses of personal data and is allowed to levy fines of up to £500,000 against major offenders.
There are 8 principles of data protection which form the core part of the Act. Businesses (and individuals) who collect personal data about people are required to act in accordance with these principles, and this page handily summarises them:
The Data Protection Act gives individuals the right to know what information is held about them. It provides a framework to ensure that personal information is handled properly.
The Act works in two ways. Firstly, it states that anyone who processes personal information must comply with eight principles, which make sure that personal information is:
* Fairly and lawfully processed
* Processed for limited purposes
* Adequate, relevant and not excessive
* Accurate and up to date
* Not kept for longer than is necessary
* Processed in line with your rights
* Secure
* Not transferred to other countries without adequate protection
The second area covered by the Act provides individuals with important rights, including the right to find out what personal information is held on computer and most paper records.
Should an individual or organisation feel they're being denied access to personal information they're entitled to, or feel their information has not been handled according to the eight principles, they can contact the Information Commissioner's Office for help. Complaints are usually dealt with informally, but if this isn't possible, enforcement action can be taken.
Essentially, you must:
- collect the minimum information necessary to accomplish a task,
- tell people what information you're collecting about them and why,
- store the information securely, making sure the minimum number of people necessary to achieve the task have access to it
- keep the information for the minimum time necessary to achieve the task, and then dispose of it securely.
People have the right to ask you for copies of all information you hold about them - and this can include any emails that refer to them (because they contain an individual's name and/or email address), so be professional when sending emails about people or forwarding things on.
The ICO have also kindly produced this checklist to help us work out whether we're acting within the principles of data protection:
* Do I really need this information about an individual? Do I know what I'm going to use it for?These principles apply to all companies operating under EU law - and, as I understand it, all non-EU companies that choose to take part in the Safe Harbor programme. Penalties for non-compliance can be quite high, so please make sure you're storing and handling data properly!
* Do the people whose information I hold know that I've got it, and are they likely to understand what it will be used for?
* If I'm asked to pass on personal information, would the people about whom I hold information expect me to do this?
* Am I satisfied the information is being held securely, whether it's on paper or on computer? And what about my website? Is it secure?
* Is access to personal information limited to those with a strict need to know?
* Am I sure the personal information is accurate and up to date?
* Do I delete or destroy personal information as soon as I have no more need for it?
* Have I trained my staff in their duties and responsibilities under the Data Protection Act, and are they putting them into practice?
* Do I need to notify the Information Commissioner and if so is my notification up to date?
Thank you Nicole. I appreciate you're efforts to bring information to this situation.
ReplyDeleteWish that these questions were being answered.