Book contents
- Frontmatter
- Contents
- Acknowledgements
- Table of statutes and case law
- Abbreviations
- 1 Introduction
- 2 Data Protection Act 1998
- 3 Definitions of personal data
- 4 The scope of the Data Protection Act
- 5 The data protection principles
- 6 Access to personal data
- 7 Data sharing
- 8 The Freedom of Information Act 2000 and Environmental Information Regulations 2004, SI 2004/3391
- 9 Scope of the Freedom of Information Act 2000 and the Environmental Information Regulations 2004
- 10 Application of exemptions and exceptions
- 11 The public interest test
- 12 Publication schemes
- 13 Compliance, the Information Commissioner and the Information Tribunal
- 14 Disclosure logs
- 15 Records management – Section 46 code of practice
- 16 Other legislation
- 17 Interaction of the legislation
- 18 Summary
- Appendix 1 Data protection principles
- Appendix 2 Flow chart of FOI
- Appendix 3 Exemptions and exceptions under the Freedom of Information Act 2000 and the Environmental Information Regulations 2004
- Appendix 4 Bibliography and useful web addresses
- Appendix 5 Published standards for records management
- Index
- Frontmatter
- Contents
- Acknowledgements
- Table of statutes and case law
- Abbreviations
- 1 Introduction
- 2 Data Protection Act 1998
- 3 Definitions of personal data
- 4 The scope of the Data Protection Act
- 5 The data protection principles
- 6 Access to personal data
- 7 Data sharing
- 8 The Freedom of Information Act 2000 and Environmental Information Regulations 2004, SI 2004/3391
- 9 Scope of the Freedom of Information Act 2000 and the Environmental Information Regulations 2004
- 10 Application of exemptions and exceptions
- 11 The public interest test
- 12 Publication schemes
- 13 Compliance, the Information Commissioner and the Information Tribunal
- 14 Disclosure logs
- 15 Records management – Section 46 code of practice
- 16 Other legislation
- 17 Interaction of the legislation
- 18 Summary
- Appendix 1 Data protection principles
- Appendix 2 Flow chart of FOI
- Appendix 3 Exemptions and exceptions under the Freedom of Information Act 2000 and the Environmental Information Regulations 2004
- Appendix 4 Bibliography and useful web addresses
- Appendix 5 Published standards for records management
- Index
Summary
Introduction
The rights of the individual to access personal data held about them are probably the most important element of the Data Protection Act. Access to third party data, while covered in this chapter, is also dealt with in Chapter 7 on data sharing. In this chapter we will be examining requests for data on a one-off basis, while in Chapter 7 we will look at sharing data on a regular basis.
It is important when considering access to establish under which legislation access is requested. To do this it is necessary to refer to the definitions of what is and what is not personal data explained in Chapter 3.
The first question to be asked is: ‘Does the data requested relate to the individual who is requesting it or does it relate to someone else?’ If the former, then it is relatively straightforward, as we shall see shortly; if the latter, many more safeguards and checks have to be observed.
Access to the data subject's personal data
Subject access request
Section 7 of the Act gives the data subject, the person whose data it is, the right of access to all data held by the data controller about that person (Section 7.1):
7 (1) Subject to the following provisions of this section and to sections 8 and 9 an individual is entitled –
(a) to be informed by any data controller whether personal data of which that individual is the data subject are being processed by or on behalf of that data controller,
(b) if that is the case, to be given by the data controller a description of –
(i) the personal data of which that individual is the data subject,
(ii) the purposes for which they are being or are to be processed and
(iii) the recipients or classes of recipients to whom they are or may be disclosed. (DPA 1998, s. 7(1))
These will be recognized as the requirements of the fair processing statement under the first data protection principle (see Chapter 5).
- Type
- Chapter
- Information
- Information Rights in PracticeThe non-legal professional's guide, pp. 45 - 66Publisher: FacetPrint publication year: 2008