Home

 
Absence
Contract of Employment
Data Protection
Discipline and Grievance
Discrimination
Dismissal
Staff  Handbook
Employment
Foreign Workers
Health and Safety
Holidays and Hours
Index
Pay and Benefits
Performance Assessment
Recruitment
Redundancy
Terms of use

 

Data Protection

Introduction

Free Advice

 

 

 

 

 

 

 

Data Protection Index

Introduction

 

Structure and Security

Communication

Employment Records

Recruitment

Employee Monitoring

Medical Testing

Access and Disclosure

Data Registration

 

External Links

On-line Data Registration

Data Information Commissioner

Small business Guidance

 

Codes of Practice

Code 1  Recruitment and Selection

Code 2  Employment Practices

Code 3 Employee monitoring at work

Code 4 Information about worker's health

The Data Protection Act sets rules for processing personal information and applies to personnel records as well as those held on computers. It also covers both facts and opinions held about the individual. There is no exemption from the legislation for small companies.

Anyone processing personal data must comply with the eight enforceable principles of good practice. They say that data must be:
 

  • Fairly and lawfully processed

  • Processed for limited purposes

  • Adequate, relevant and not excessive

  • Accurate

  • Not kept longer than necessary

  • Processed in accordance with the data subject's rights

  • Secure

  • Not transferred to countries without adequate protection.

Please note:  The Information commissioner has published a number of codes of practice which give advice on a range of Data Protection issues.  In total these run into several hundred pages.  In this website we have picked out what we think is a sensible course for small businesses but it may not fully comply with the Commissioner's views.  Full details of the Codes of Practice are available on their website (link given opposite).