Monday, 17 February 2014

Data security & Legal issues

Q1- What is the Data Protection Act ?


A1) The Data Protection Act 1998 (DPA) is a United Kingdom Act of Parliament which defines UK law on the processing of data on identifiable living people.

Copyright © 2014 by Mohammed AL-Qubtan   


Q2- What is Information Commissioner?

A2) It is a title given to a government regulator in the fields of freedom of information and the protection of personal data in the widest sense. The office often functions as a specialist ombudsman service.

(( An ombudsman or public advocate is usually appointed by the government or by parliament, but with a significant degree of independence, who is charged with representing the interests of the public by investigating and addressing complaints of maladministration or violation of rights )).



Q3- What is the data controller?

A3) Its a  party who, according to domestic law, is competent to decide about the contents and use of personal data, regardless of whether or not such data is collected, stored, processed, or disseminated by that party or by an agent on its behalf.

Copyright © 2014 by Mohammed AL-Qubtan   


Q4- Who are the data subject?

A4) A data subject is an identified or identifiable person to whom the personal data relate, or an individual who is the subject of personal data.


Q5- Who are the data users?

A5) The data users are people which are responsible of a data and only have the rights to use it.


Q6- What is personal data?

A6) Personal data is any recorded information about an identifiable individual, such as a person's religion, age, financial transactions, medical history, address, or blood type. The term includes both identifying personal information and non-identifying personal information.

Copyright © 2014 by Mohammed AL-Qubtan   


The Eight points of the Data Protection Act: 


1- Personal data shall be processed fairly and lawfully.

2- Personal data shall be obtained only for one or more specified and lawful purposes, and shall not be further processed in any manner incompatible with that purpose or those purposes.

3- Personal data shall be adequate, relevant and not excessive in relation to the purpose or purposes for which they are processed.

4- Personal data shall be accurate and, where necessary, kept up to date.

5- Personal data processed for any purpose or purposes shall not be kept for longer than is necessary for that purpose or those purposes.

6- About the rights of individuals e.g. personal data shall be processed in accordance with the rights of data subjects (individuals).

7- Appropriate technical and organisational measures shall be taken against unauthorised or unlawful processing of personal data and against accidental loss or destruction of, or damage to, personal data.


8- Personal data shall not be transferred to a country or territory outside the European Economic Area unless that country or territory ensures an adequate level of protection for the rights and freedoms of data subjects in relation to the processing of personal data.


References: 
1- http://en.wikipedia.org/wiki/Data_Protection_Act_1998

2- http://dictionary.cambridge.org/dictionary/business-english/information-commissioner


No comments:

Post a Comment