APPENDICES

  • Principle 6 – Personal data shall be processed in accordance with the rights of data sub- jects under this Act.
  • Principle 7 – Appropriate technical and organisational measures shall be taken against unauthorised or unlawful processing of personal data and against accidental loss or de- struction of, or damage to, personal data.
  • Principle 8 – Personal data shall not be transferred to a country or territory outside the European Economic Area unless that country or territory ensures an adequate level of protection for the rights and freedoms of data subjects in relation to the processing of personal data.

4.25 Attention is usually focused on the first data protection principle which imposes a three

fold obligation on the data controller: fairness, lawfulness and compliance with one of six specified conditions in Schedule 2.346 Schedule 2 introduces concepts such as consent of the data subject and necessity in order to fulfill a legitimate aim; for example, compliance with a contract, a legal obligation, to protect the vital interests of the data subject, to promote the administration of justice, or the exercise of public functions in the public interest. Special conditions apply for the purposes of the first data protection principle if the relevant data is "sensitive" personal data.347 These requirements are set out in Schedule 3 to the Act and include: explicit consent to processing, processing to be necessary for exercising or performing any right or obligation conferred or imposed by law in connection with employment, processing to be necessary to protect vital interests of the data subject or another person, or information having been made public by steps deliberately taken by the data subject.

Rights of a data subject 4.26 The Act confers a number of rights on data subjects.348 These rights include:

(a) the right to be informed by any data controller whether personal data of which that individual is the data subject are being processed by or on behalf of that data controller; (b) if that is the case, to be given by the data controller a description of the personal data, the purposes for which they are being processed and the recipients or classes of recipients to whom they are or may be disclosed; (c) to have communicated the personal data to him or her in an intelligible form. Where a data controller cannot comply with the request without disclosing information relating to another individual who can be identified from that information, he or she is not obliged to comply with the request unless (a) the other individual has consented to the disclosure of the information to the person making the request, or (b) it is reasonable in all the circumstances to comply with the request without the consent of the other individual.349

4.27 The Act also confers on a data subject a number of further rights to require data processing

to cease, or not to begin where that processing is likely to cause distress or damage, or where the processing is for the purposes of direct marketing of personal data in respect of which a person is the data subject, and to require the data controller to ensure that no decision taken by or on behalf of the data controller which significantly affects that individual is based solely on the processing by automatic means of personal data.350

1909

4.28 Section 13 provides that an individual who suffers damage by reason of any contravention

by a data controller of any of the requirements of the Act is entitled to compensation from the data controller for that damage. Further, an individual who suffers distress by reason of any contravention by a data controller of any of the requirements of the Act is entitled to compensation from the data controller for that damage if the individual also suffers damage by reason of the contravention or the contravention relates to the processing of personal data for the special purposes.351 In practice relatively small sums have been award by way of damages, namely in the region of £50 to £5000.352 In April 2010 the Commissioner acquired the power under s55A to impose a monetary penalty if the Commissioner is satisfied that; (a) there has been a serious contravention of s4(4) by the data controller, (b) the contravention was of a kind likely to cause substantial damage or substantial distress, and (c) the contravention was deliberate or the data controller knew or ought to have known of the risk of contravention, likelihood of causing substantial damage or distress and failed to take reasonable steps to prevent the contravention.

Restrictions on data controllers 4.29 Part III of the Act imposes certain notification requirements on data controllers. Personal

data must not be processed unless an entry in respect of the data controller is included in the register maintained by the Commissioner under s19.353 Failure to comply with this constitutes an offence, subject to a defence that the controller exercised all due diligence to comply with the duty.354 A data controller wishing to be included in the register must notify the Commissioner and the commissioner must maintain a register of persons who have given notification under section 18.355

Exemptions 4.30 Part IV sets out exemptions from compliance with certain obligations in the Act, where the

obligations potentially conflict with other important public interest considerations.356 The exemptions disapply some of the data protection principles and some of the requirements of the Act imposed on data controllers. The relevant exemptions cover national security, crime and taxation, health education and social work, regulatory activity, journalism, literature and art, research history and statistics, manual data held by public authorities, information available to the public under an enactment, disclosures required by law or made in connection with legal proceedings, parliamentary privilege and domestic purposes. Schedule 7 to the Act sets out further miscellaneous exemptions.

1910