Data Protection
Most modern websites include a lot of interaction and in many cases they will also collect some personal information about users. The Data Protection Act 1998 requires organisations which hold personal data to protect the privacy of the people that data relates to and process personal information in accordance with the eight principles laid down in the act. In layman’s terms these principles are:
- Personal data should be processed fairly and in accordance with the law.
- Personal data must only be obtained for specific and lawful purposes.
- Personal data should only be held if it is necessary and relevant to the specified purposes – particularly where the information is sensitive.
- Personal data should be accurate and kept up-to-date.
- Personal data should not be kept any longer than necessary.
- Personal data should be processed in accordance with the rights of the people it relates to.
- Appropriate technical and organisational measures should be in place for the security of personal data.
- Personal information should not be transferred outside the European Economic Area unless adequate protection is in place.
