Using personal data, policies and record-keeping
This section provides a general overview of your The area of law which deals with the way in which data can be handled. obligations and the circumstances in which you can legally use Any information about an identifiable, living person. Information which cannot be used to identify someone on its own will still be personal data if it can be used in combination with other information to identify that individual.. This includes helping you to create suitable policies, understanding when you will need to carry out an impact assessment or appoint a The area of law which deals with the way in which data can be handled. In a company: A legally defined term used to refer to the director, company secretary or managers of a company. Officers of a company have certain duties and responsibilities towards the company and can be held liable for company law breaches., what training you need to provide Anybody who works for a business, whether as an employee, casual worker, apprentice, agency worker or freelancer. and the records you are required to keep.
Data protection obligations
- 1.What is a data controller?
- 2.If my business is a data controller, what are my data protection obligations?
- 3.What is a data processor?
- 4.If my business is a data processor, what are my data protection obligations?
- 5.Can I insure against fines for failing to follow data protection law?
- 6.What data protection policies does my business need?
- 7.How did Brexit affect my data protection obligations?
When to use personal data
- 8.When can my business use personal data?
- 9.Can I use someone's personal data to fulfil an order they have placed?
- 10.Can I use someone's personal data if the law requires me to?
- 11.What does a legitimate interest to use someone's personal data mean?
- 12.Can I use someone's personal data if I have a legitimate interest in doing so?
- 13.What is sensitive personal data?
- 14.When can my business use sensitive personal data?
- 15.What are my business's data protection obligations for sensitive personal data?
- 16.What are my business's data protection obligations for children's personal data?
- 17. Can my business use facial recognition technology?
- 18.Do I need a separate policy for sensitive personal data?
- 19.When can my business use data about criminal convictions?
- 20.What information must I give people about using their personal data?
- 21.When must I provide privacy information to individuals whose data I am using?
- 22.How should I provide privacy information to individuals whose data I am using?
Consent to use personal data
- 23.Do I need consent to use personal data?
- 24.How do I get consent to use personal data?
- 25.Can children give me consent themselves to use their data over the internet?
- 26.Do I have to keep a record of the consents I have received to use personal data?
- 27.How do I explain clearly what the consent to use personal data is for?
- 28.How do I get people to actively give their consent to use their personal data?
- 29.How do I make sure the consent request to use personal data is separate from other information?
- 30.How do I make sure someone is not pressured into giving consent to use their personal data?
- 31.How do I tell people they are free to withdraw their consent to use their personal data?
- 32.Do I need consent to use personal data for direct marketing?
- 33.Do I need consent to share personal data with other businesses?
- 34.Do I need consent to use sensitive personal data?
- 35.How do I get consent to use sensitive personal data?
ICO registration and fees
Data protection impact assessments
- 39.What is a data protection impact assessment?
- 40.Do I have to carry out a data protection impact assessment if I am a data processor?
- 41.When must I carry out a data protection impact assessment?
- 42.What if I should have carried out a data protection impact assessment, but I didn't?
- 43.How do I carry out a data protection impact assessment?
- 44.What does the ICO recommend for data protection impact assessments?
- 45.What should I do once I have completed a data protection impact assessment?
Data protection officers and staff training
Record-keeping
- 50.What data protection records do I need to keep to show I have followed data protection rules?
- 51.What data protection consent records do I need to keep?
- 52.What data protection officer records do I need to keep?
- 53.What internal data protection policy records do I need to keep?
- 54.What records on personal data breaches do I need to keep?
- 55.What records on data protection impact assessments do I need to keep?
- 56.What data processing records do I need to keep if I am a data controller?
- 57.What data processing records do I need to keep if I am data processor?
- 58.What contract records do I have to keep if I share personal data?