Menu
Menu
Data Protection Part 1 – What You Need To Know
Transcript
Welcome.
This is a short training video from Support Cambridgeshire, the first in a series on data protection.
We’re looking at the essentials of data protection law. In other words, what you need to know.
Let’s see what we’re going to cover.
We’ll begin with a short look at why privacy matters, and then we’ll move to the principles behind data protection, which are set out in law.
Then we’ll look at the lawful reasons for which you can process personal data. Finally, we’ll finish off this video with a look at individual data protection rights.
But before we begin, let’s remind ourselves what we mean by personal data.
What we mean by personal data
Personal data is any piece of information, including a photograph, from which an individual can be identified.
So name, address, payroll number, or bank account number, for example, are all forms of personal data.
But things like hair colour, shoe size, and town of birth are not personal data because, on their own, none of these things can identify a single individual.
Of course, when you combine certain data, such as a person’s race with their name, for example, then both would be classed as personal data.
Learn more about Key Data Protection Terms.
Why privacy matters
Okay, so why should we be bothered about privacy? Isn’t it just common sense?
Well, it’s much more than that. We all have a right to privacy, and if that right is broken, then the consequences can be severe.
For example, the release of personal data about health conditions or perhaps trade union membership could result in discrimination or even dismissal by an employer.
Of course, criminals use personal data for identity theft and fraud, blackmail, ransom, and other threats.
But failing to respect privacy can damage voluntary organisations as well.
For a charity, it can lead to bad publicity, damage to reputation, loss of support and funding, fines, and the extra costs of putting things right.
That’s why we have data protection laws, namely the UK GDPR, which is how it’s known following Brexit, and the 2018 Data Protection Act. But what do these laws say?
The principles behind data protection
Helpfully, the UK GDPR sets out a number of principles by which personal data must be processed. Follow these, and you shouldn’t get into trouble with the law.
The first principle is that you must have a lawful reason or basis for your processing. There are six of these, which we shall look at later.
Next, you can only use the data for the purpose it was collected.
For example, you can’t use someone’s details for sending them funding requests if you’ve only said you will use it to provide a particular service.
The third principle says you must only collect and process data that is necessary, so you should not ask for a postal address if you only ever intend to email someone.
The fourth principle is that the data you process must be accurate. This means you must take reasonable steps to keep it up to date.
Fifth, it should be kept for no longer than is actually necessary. Once it’s not needed, it should be deleted.
And six, it must be secure. This means you need good cyber and physical security for the data.
Finally, the seventh principle says you are accountable for how you handle data, so you need to make sure you can demonstrate compliance with the law.
Now, as we’ve seen, the first principle of data protection is that you can only process data for a lawful reason.
Lawful reasons on which data can be processed
Let’s just look at the six lawful reasons, sometimes called bases, on which data can be processed.
The first reason or lawful basis for processing personal data is consent. To be valid, this consent must be freely given by clear, affirmative action for each processing reason.
There can be no generic or bundled up consents and no pre-tick boxes for someone to untick. Finally, it must be easy to opt out, withdraw or revoke consent at any time.
The next lawful reason for processing is contractual. This is where we process data with a view to entering into or operating a contract.
Processing personal details, such as in a quote for some work, is a contractual reason for data processing.
We now come to legitimate interest. This is a useful reason to have for data processing because it’s so flexible. However, the small print says that your interest must not override the privacy interests of the individual, so the processing has to be something transparent that the data subject would expect.
A business interest, for example, can be a legitimate interest if it is clear and expected. A good example might be processing the names of individuals who have applied to attend a training course.
Clearly, you can’t process applications without collecting names. Anyone who signs up would expect you to do this, so there is no hidden processing or undermining of an individual’s privacy.
The fourth of our six reasons is legal obligation. This is where you are required to process the data by law.
For example, an employer has a legal duty to collect income tax through Pay As You Earn, which clearly requires the processing of personal data.
The next reason is vital interest. It applies in very limited circumstances, specifically when there is a risk to life.
The sixth and final lawful reason applies to public authorities and elected officials, such as a councillor or member of parliament.
Here, personal data can be processed lawfully, specifically in order to provide a service or to perform a public task.
Individual legal rights
The next part of this video involves looking at the individual legal rights people have on how their data is processed, all of which are enforced by a regulator, the ICO (Information Commissioner’s Office).
So what are these rights?
Top of the list is the right to be informed about how and why your data is processed. This is usually set out in a privacy notice, which must be provided at the point that personal data is collected.
We cover privacy notices in the third video in this series.
You also have a right to access your personal data that an organisation is processing.
This is enacted through a “subject access request”.
Next, you have a right to have errors rectified once the organisation has been made aware of the error.
And you have a right to restrict processing.
This limits how data can be used and usually applies when the accuracy of data is contested or while an objection to data processing is being considered, which leads nicely into your specific right to object to processing in certain circumstances.
For example, if you object to your data being used for direct marketing, or if you question why an organisation is relying upon their legitimate interest as the lawful reason for the data processing.
You also have a right to be forgotten, that is, to have data erased when data is no longer needed. For example, if the data is historical or if you have withdrawn consent for processing.
Perhaps not used quite so often is the right to data portability, which allows you to reuse your data for your own purposes across different services. This is how, for example, insurance comparison sites work.
Finally, you have certain rights in relation to high-volume automated processing and profiling.
This is something used to evaluate an individual based on their personal data and decide, for example, what products they may like to buy.
Okay, that’s all we’re covering in this video, so let’s quickly recap.
To protect privacy, you should comply with the seven data protection principles, which include processing data securely and being accountable for what you do.
You should always have a lawful basis for every data processing operation.
Finally, you should uphold the data protection rights of individuals, which, among other things, means providing privacy information.
For practical advice on compliance with the law, please look out for the other titles in this Data Protection Series.
And to learn more about the areas we have covered in this video, please refer to the ICO website.
Guidance links
Who needs to register with the Information Commissioner’s office
Data protection fee self-assessment
Freedom of Information
Subject Access Requests
The soft “opt-in”
Guidance on direct marketing
Privacy notice generator tool
Writing a data protection policy and procedures
AI and data protection