|
For every business owner, no matter how small, there’s a responsibility in relation to personal data which cannot be ignored. The 1998 Data Protection Act made sure of that.
Every business owner should start by asking themselves two simple questions:
Firstly, do you need to register under the Act? The Act requires the Information Commissioner to maintain a Register of data ‘controllers’ and the purposes for which they use personal information. Data controllers are those who are responsible for processing personal information. To ‘process’ information you only have to store it or receive it. You do not have to be ‘active’ in any way. As the owner of a small business you will almost certainly ‘process’ data, in the form of personal information, even if it’s only about your own staff.
Secondly, do you comply with the Act? In summary the Act makes requirements that data:
- Be fairly and lawfully processed
- Only be processed for specified purposes
- Is adequate for the purpose for which it is collected, relevant and not excessive
- Is accurate, and where necessary, kept up to date
- Is not kept for longer than is necessary
- Is processed in line with the rights of the individual
- Data is kept secure
- Is not transferred to countries outside the European Economic Area unless there is adequate protection for the information
If you have any doubts in relation to any of these points you really should take a closer look or take advice.
For those who employ people data protection responsibilities can be even more onerous. Our article Employment and Data Protection provides more details.
Data Protection is a complex area of law with many nuances. For individual advice on your data protection responsibilities as a business owner or the steps you need to take to ensure your employees are compliant call Andrew Woolley on 01789 267377 or email info@business-lawfirm.co.uk. |