Is buying data legal and GDPR compliant?

This is a complicated question, but in short, using bought data is legal and in line with GDPR (General Data Protection Regulations). HOWEVER, this is only the case if it has been purchased in the right way, from the right source. GDPR states that, to contact an individual, you need explicit consent from them. Most […]

Read More… from Is buying data legal and GDPR compliant?

Special category data

Special category data is personal data that needs more protection because it is sensitive.In order to lawfully process special category data, you must identify both a lawful basis under Article 6 of the UK GDPR and a separate condition for processing under Article 9. These do not have to be linked.You need to complete a data […]

Read More… from Special category data

Principle (c): Data minimisation

What is the data minimisation principle? Article 5(1)(c) says: “1. Personal data shall be: (c) adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed (data minimisation)” So you should identify the minimum amount of personal data you need to fulfil your purpose. You should hold that […]

Read More… from Principle (c): Data minimisation

Data sharing: a code of practice

The UK Government has laid the Data Sharing Code of Practice before Parliament on 18 May 2021. It will lay before Parliament for 40 sitting days before coming into force. In 2011 the ICO published its first Data Sharing Code; in the intervening period the type and amount of data collected by organisations has changed […]

Read More… from Data sharing: a code of practice

What is a GDPR data processing agreement?

Virtually every business relies on third parties to process personal data. Whether it’s an email client, a cloud storage service, or website analytics software, you must have a data processing agreement with each of these services to achieve GDPR compliance. What needs to be in a data processing agreement GDPR Article 28 Section 3, explains […]

Read More… from What is a GDPR data processing agreement?

Wissen Sie, wie man eine SAR erkennt?

As per the GDPR Regulative there are certain rights that data subjects can obtain. One of the rights is the Right to Access . The right of access, commonly referred to as subject access, gives individuals the right to obtain a copy of their personal data, as well as other supplementary information. It helps individuals to […]

Read More… from Do you know how to recognize a SAR?

ICO POST: Data sharing code

Very beneficial blog has been shared by Ali Shah, Head of Technology Policy Blog:Building on the data sharing code: our plans for updating our anonymisation guidance. Data is the lifeblood of the digital economy, and the sharing of personal data is key to opening up new opportunities. Data shared in healthcare environments can map out […]

Read More… from ICO POST: Data sharing code

5 Facts about Data Protection  

Data protection is one of the most important topics of discussion in this expanding digital world . A lot of people and companies are not aware of what this means, and they would need to gain additional knowledge in order to understand the true meaning of this . Here are some facts about Data privacy […]

Read More… from 5 Facts about Data Protection  

Are you aware of holding sensitive data ?

Sensitive data is information that must be protected against unauthorized access. Access to sensitive data should be limited through sufficient data security and information security practices designed to prevent unauthorized disclosure and data breaches. Your organization may have to protect sensitive data for ethical or legal requirements, personal privacy, regulatory reasons, trade secrets and other […]

Read More… from Are you aware of holding sensitive data ?

Can I collect data about whether my employees are vaccinated against COVID-19?

Before you decide to collect your employees vaccination status, you should be clear about what you are trying to achieve and how recording staff vaccination status will help you to achieve this. Whether your employee has been vaccinated is their private health information and is therefore special category data. Your use of this data must […]

Read More… from Can I collect data about whether my employees are vaccinated against COVID-19?