APPENDICES
¶4.17 The European Parliament adopted the Directive on 24 October 1995 and in March 1996 the
Home Office issued a consultation paper on the Directive. The Secretary of State for the Home Department subsequently presented proposals for new data protection legislation, which took the form of the Data Protection Act 1998.
Data Protection Act 1998 Introduction
¶4.18 The Data Protection Act 1998 (the DPA) replaced the Data Protection Act 1984 and sought to
implement the provisions of the Data Protection Directive by establishing a system of data protection controls for manual data as well as computerised data. Lord Williams of Mostyn commenced his second reading speech for the Data Protection Bill on 2 February 1998 with the following comments:334
"The Bill will improve the position of citizens of his country by enabling them to rely on a wide range of civil and political rights contained in the European Convention on Human Rights. Those rights include the right to respect for private and family life. The Data Protection Bill also concerns privacy, albeit a specific form of privacy; personal information privacy."
¶Key concepts and structure of the Data Protection Act 1998 4.19 In broad terms, the DPA seeks to ensure that personal data is used in accordance with the data
protection principles, attaches certain conditions to the processing of personal data and adds extra safeguards where the personal data is sensitive. The DPA also establishes certain rights for a data subject and establishes a framework of enforcement. The legislation responds to the requirement to protect the privacy of recorded information relating to an individual.
¶4.20 At the heart of the DPA are a number of defined terms used throughout the Act. It is important
1907to understand these. "Data" means information processed by automatic equipment, information recorded with the intention of being processed by such equipment, information held in relevant filing systems and recorded information held by a public authority.335 "Personal data" means data which relate to a living individual.336 "Processing" encompasses a wide range of uses of data including obtaining, recording, holding, organising, altering, adapting, retrieving, using and disclosing data.337 Processing also includes putting data into print, namely publication.338 "Data controller" means the person or organisation who determines the purpose for which and the manner in which any personal data are processed, i.e who
¶Appendix 4 | Legal Materials
decides what is to be done with the information.339 The definition of data controller includes the press and media organisations. "Data processor" is the person who processes the data on behalf of the data controller.340
¶4.21 Certain types of personal data are defined as sensitive personal data.341 This includes
information as to (a) the racial or ethnic origin of the data subject, (b) political opinions, (c) religious beliefs or other beliefs of a similar nature, (d) membership of a trade union, (e) physical or mental health or condition342, (f) sexual life, and (g) the commission or alleged commission of any offence, proceedings relating to this or disposal of such proceedings.
¶4.22 The DPA applies to a data controller in respect of any data where the data controller is
established in the UK and the data is processed in the context of that establishment or the data controller uses equipment in the UK for the processing of data other than for the purpose of transit through the UK.343 p57, lines 9-14, Chris Elliott, ibid pp42-43, lines 22-3, Philip Williams, http://www.levesoninquiry.org.uk/wp-content/uploads/2012/02/Transcript-of- Morning-Hearing-29-February-2012.pdf http://www.pcc.org.uk/news/index.html?article=NjIyOQ; http://www.pcc.org.uk/news/index.html?article=NjIyOA p8, Metropolitan Police Service, http://www.levesoninquiry.org.uk/wp-content/uploads/2012/03/MPS-24-Notices- 06-12-Policy-and-Standard-Operating-Procedure.pdf p54, ibid. There was a further inconsequential text from Mr Michel to Mr Hunt later that evening: "You too mon ami! Fred", p56, ibid p89, para 6, http://www.levesoninquiry.org.uk/wp-content/uploads/2012/07/Submission-by-Media-Standards- Trust.pdf Defined in ss1(1), 5(1)
¶4.23 The DPA further sets out that it shall be the duty of a data controller to comply with the data
protection principles in relation to all personal data with respect to which he or she is the data controller.344 This duty is subject to section 27, which introduces the exemptions in Part IV of the Act. Breach of this statutory duty to comply with the data protection principles gives rise to a private law cause of action, allowing the data subject to make a claim against the data controller.
¶4.24 The data protection principles define the manner in which all personal data must be processed.
¶These principles are set out in Part 1 of Schedule 1 of the Act:
1908
- Principle 1 – Personal data shall be processed fairly and lawfully and, in particular, shall not be processed unless (a) at least one of the conditions in Schedule 2 is met, and (b) in the case of sensitive personal data, at least one of the conditions in Schedule 3 is also met.345
- Principle 2 – Personal data shall be obtained only for one or more specified and lawful purposes, and shall not be further processed in any manner incompatible with that pur- pose or those purposes.
- Principle 3 – Personal data shall be adequate, relevant and not excessive in relation to the purpose or purposes for which they are processed.
- Principle 4 – Personal data shall be accurate and, where necessary, kept up to date.
- Principle 5 – Personal data processed for any purpose or purposes shall not be kept for longer than is necessary for that purpose or those purposes.