Jump to content
 







Main menu
   


Navigation  



Main page
Contents
Current events
Random article
About Wikipedia
Contact us
Donate
 




Contribute  



Help
Learn to edit
Community portal
Recent changes
Upload file
 








Search  

































Create account

Log in
 









Create account
 Log in
 




Pages for logged out editors learn more  



Contributions
Talk
 



















Contents

   



(Top)
 


1 Background  





2 Contents  



2.1  Scope of protection  





2.2  Data protection principles  





2.3  Exceptions  





2.4  Police and court powers  





2.5  Offences  





2.6  Complexity  





2.7  Definition of personal data  





2.8  Subject access requests  





2.9  Information Commissioner  





2.10  EUs Article 29 Working Party  







3 See also  





4 References  





5 External links  



5.1  UK legislation  
















Data Protection Act 1998






Deutsch
Français

 

Edit links
 









Article
Talk
 

















Read
Edit
View history
 








Tools
   


Actions  



Read
Edit
View history
 




General  



What links here
Related changes
Upload file
Special pages
Permanent link
Page information
Cite this page
Get shortened URL
Download QR code
Wikidata item
 




Print/export  



Download as PDF
Printable version
 
















Appearance
   

 






From Wikipedia, the free encyclopedia
 


Data Protection Act 1998
Act of Parliament
Long titleAn Act to make new provision for the regulation of the processing of information relating to individuals, including the obtaining, holding, use or disclosure of such information.
Citation1998 c. 29
Territorial extent 
  • England and Wales
  • Scotland
  • Northern Ireland
  • Dates
    Royal assent16 July 1998
    Other legislation
    Repeals/revokesData Protection Act 1984
    Repealed byData Protection Act 2018

    Status: Repealed

    Text of statute as originally enacted
    Data Protection Act 1984
    Act of Parliament
    Long titleAn Act to regulate the use of automatically processed information relating to individuals and the provision of services in respect of such information.
    Citation1984 c. 35
    Dates
    Royal assent12 July 1984
    Repealed1 March 2000
    Other legislation
    Repealed byData Protection Act 1998

    Status: Repealed

    Text of statute as originally enacted

    The Data Protection Act 1998 (c. 29) (DPA) was an Act of Parliament of the United Kingdom designed to protect personal data stored on computers or in an organised paper filing system. It enacted provisions from the European Union (EU) Data Protection Directive 1995 on the protection, processing, and movement of data.

    Under the 1998 DPA, individuals had legal rights to control information about themselves. Most of the Act did not apply to domestic use,[1] such as keeping a personal address book. Anyone holding personal data for other purposes was legally obliged to comply with this Act, subject to some exemptions. The Act defined eight data protection principles to ensure that information was processed lawfully.

    It was superseded by the Data Protection Act 2018 (DPA 2018) on 23 May 2018. The DPA 2018 supplements the EU General Data Protection Regulation (GDPR), which came into effect on 25 May 2018. The GDPR regulates the collection, storage, and use of personal data significantly more strictly.[2]

    Background

    [edit]

    The 1998 Act replaced the Data Protection Act of 1984 and the Access to Personal Files Act of 1987. Additionally, the 1998 Act implemented the EU Data Protection Directive 1995.

    The Privacy and Electronic Communications (EC Directive) Regulations 2003 altered the consent requirement for most electronic marketing to "positive consent" such as an opt-in box. Exemptions remain for the marketing of "similar products and services" to existing customers and enquirers, which can still be permitted on an opt-out basis.

    The Jersey data protection law was modelled on the United Kingdom's law.[3]

    Contents

    [edit]

    Scope of protection

    [edit]

    Section 1 of DPA 1998 defined "personal data" as any data that could have been used to identify a living individual. Anonymised or aggregated data was less regulated by the Act, provided the anonymisation or aggregation had not been done reversibly. Individuals could have been identified by various means including name and address, telephone number, or email address. The Act applied only to data which was held, or was intended to be held, on computers ("equipment operating automatically in response to instructions given for that purpose"), or held in a "relevant filing system".[4]

    In some cases, paper records could have been classified as a relevant filing system, such as an address book or a salesperson's diary used to support commercial activities.[5]

    The Freedom of Information Act 2000 modified the act for public bodies and authorities, and the Durant case modified the interpretation of the act by providing case law and precedent.[6]

    A person who had their data processed had the following rights:[7][8]

    Data protection principles

    [edit]

    Schedule 1 listed eight "data protection principles":

    1. Personal data shall be processed fairly and lawfully and, in particular, shall not be processed unless:
      1. at least one of the conditions in Schedule 2 is met, and
      2. in the case of sensitive personal data, at least one of the conditions in Schedule 3 is also met.
    2. Personal data shall be obtained only for one or more specified and lawful purposes, and shall not be further processed in any manner incompatible with that purpose or those purposes.
    3. Personal data shall be adequate, relevant and not excessive in relation to the purpose or purposes for which they are processed.
    4. Personal data shall be accurate and, where necessary, kept up to date.
    5. Personal data processed for any purpose or purposes shall not be kept for longer than is necessary for that purpose or those purposes.
    6. About the rights of individuals e.g.[13] personal data shall be processed in accordance with the rights of data subjects (individuals).
    7. Appropriate technical and organisational measures shall be taken against unauthorised or unlawful processing of personal data and against accidental loss or destruction of, or damage to, personal data.
    8. Personal data shall not be transferred to a country or territory outside the European Economic Area unless that country or territory ensures an adequate level of protection for the rights and freedoms of data subjects in relation to the processing of personal data.

    Broadly speaking, these eight principles were similar to the six principles set out in the GDPR of 2016.[14]

    Conditions relevant to the first principle

    Personal data should only be processed fairly and lawfully. In order for data to be classed as 'fairly processed', at least one of these six conditions had to be applicable to that data (Schedule 2).

    1. The data subject (the person whose data is stored) has consented ("given their permission") to the processing;
    2. Processing is necessary for the performance of, or commencing, a contract;
    3. Processing is required under a legal obligation (other than one stated in the contract);
    4. Processing is necessary to protect the vital interests of the data subject;
    5. Processing is necessary to carry out any public functions;
    6. Processing is necessary in order to pursue the legitimate interests of the "data controller" or "third parties" (unless it could unjustifiably prejudice the interests of the data subject).[15]
    Consent

    Except under the exceptions mentioned below, the individual had to consent to the collection of their personal information [16] and its use in the purpose(s) in question. The European Data Protection Directive defined consent as “…any freely given specific and informed indication of his wishes by which the data subject signifies his agreement to personal data relating to him being processed", meaning the individual could have signified agreement other than in writing.[citation needed] However, non-communication should not have been interpreted as consent.

    Additionally, consent should have been appropriate to the age and capacity of the individual and other circumstances of the case. If an organisation "intends to continue to hold or use personal data after the relationship with the individual ends, then the consent should cover this." When consent was given, it was not assumed to last forever, though in most cases, consent lasted for as long as the personal data needed to be processed, and individuals may have been able to withdraw their consent, depending on the nature of the consent and the circumstances in which the personal information was collected and used.[17]

    The Data Protection Act also specified that sensitive personal data must have been processed according to a stricter set of conditions, in particular, any consent must have been explicit.[17]

    Exceptions

    [edit]

    The Act was structured such that all processing of personal data was covered by the act while providing a number of exceptions in Part IV.[1] Notable exceptions were:

    Police and court powers

    [edit]

    The Act granted or acknowledged various police and court powers.

    Offences

    [edit]

    The Act detailed a number of civil and criminal offences for which data controllers may have been liable if a data controller failed to gain appropriate consent from a data subject. However, consent was not specifically defined in the Act and so was a common law matter.

    Complexity

    [edit]

    The UK Data Protection Act was a large Act that had a reputation for complexity.[25] While the basic principles were honored for protecting privacy, interpreting the act was not always simple. Many companies, organisations, and individuals seemed very unsure of the aims, content, and principles of the Act. Some refused to provide even very basic, publicly available material, quoting the Act as a restriction.[26] The Act also impacted the way in which organisations conducted business in terms of who should have been contacted for marketing purposes, not only by telephone and direct mail, but also electronically. This has led to the development of permission-based marketing strategies.[27]

    Definition of personal data

    [edit]

    The definition of personal data was data relating to a living individual who can be identified

    Sensitive personal data concerned the subject's race, ethnicity, politics, religion, trade union status, health, sexual history, or criminal record.[28]

    Subject access requests

    [edit]

    The Information Commissioner's Office website stated regarding subject access requests:[29] "You have the right to find out if an organisation is using or storing your personal data. This is called the right of access. You exercise this right by asking for a copy of the data, which is commonly known as making a 'subject access request.'"

    Before the General Data Protection Regulation (GDPR) came into force on 25 May 2018, organisations could have charged a specified fee for responding to a SAR of up to £10 for most requests. Following GDPR: "A copy of your personal data should be provided free. An organisation may charge for additional copies. It can only charge a fee if it thinks the request is 'manifestly unfounded or excessive'. If so, it may ask for a reasonable fee for administrative costs associated with the request."[29]

    Information Commissioner

    [edit]

    Compliance with the Act was regulated and enforced by an independent authority, the Information Commissioner's Office, which maintained guidance relating to the Act.[30][31]

    EU’s Article 29 Working Party

    [edit]

    In January 2017, the Information Commissioner's Office invited public comments on the EU's Article 29 Working Party's proposed changes to data protection law and the anticipated introduction of extensions to the interpretation of the Act, the Guide to the General Data Protection Regulation.[32]

    See also

    [edit]

    References

    [edit]
    1. ^ a b Data Protection Act 1998, Part IV (Exemptions), Section 36 Archived 24 August 2007 at the Wayback Machine, Office of Public Sector Information, accessed 6 September 2007
  • ^ Ford, Michael (March 1999). "Recent legislation. The Data Protection Act 1998". Industrial Law Journal. 28: 57–60. doi:10.1093/ilj/28.1.57.
  • ^ Jersey: Data Protection In Jersey And Other Offshore Jurisdictions Archived 27 October 2012 at the Wayback Machine 23 July 2008 Article by Wendy Benjamin, mondaq.com,
  • ^ "Data Protection Act 1998, Basic interpretative provisions". Office of Public Sector Information. Archived from the original on 1 March 2014. Retrieved 14 March 2014.
  • ^ "Determining what information is 'data' for the purposes of the DPA" (PDF). Information Commissioner's Office. 16 March 2012. Archived (PDF) from the original on 22 July 2016. Retrieved 2 March 2018.
  • ^ "What is personal data? Information Commissioner updates guidance". Pinsent Masons. 30 August 2007. Archived from the original on 20 October 2011. Retrieved 20 August 2012. In the case involving Michael Durant he sought information held on him by the Financial Services Authority. The Court of Appeal ruled that just because a document contained his name it was not necessarily defined as personal data. This changed the perception of how wide a definition of personal data could be.
  • ^ Your rights[permanent dead link], ICO, accessed 6 September 2007
  • ^ "The rights of individuals (Principle 6) Archived 18 November 2016 at the Wayback Machine", ICO, accessed 7 December 2016
  • ^ "FAQs". Information Commissioner's Office. Archived from the original on 30 May 2013. Retrieved 19 January 2014.
  • ^ "Claiming compensation". Information Commissioner's Office. Archived from the original on 21 June 2017. Retrieved 24 November 2017.
  • ^ Data Protection Act 1998, Part II (Rights of data subjects and others), Section 10 Archived 5 September 2011 at the Wayback Machine, Office of Public Sector Information, accessed 6 September 2007
  • ^ Data Protection Act 1998, Part II (Rights of data subjects and others), Section 11 Archived 4 September 2011 at the Wayback Machine, Office of Public Sector Information, accessed 6 September 2007
  • ^ The rights of individuals (Principle 6), ICO.org.uk, accessed 14 April 2011
  • ^ Maxwell, F., Six Principles of GDPR, Quality Compliance Systems Ltd., published 3 February 2020, accessed 3 January 2024
  • ^ OPSI.gov.uk Archived 16 April 2009 at the Wayback Machine Data Protection Act 1998 Schedule 2
  • ^ Sarah, Featherstone (28 May 2021). "How to Comply with GDPR". Archived from the original on 29 May 2021.
  • ^ a b "Conditions for Processing – Guide to Data Protection – ICO". Information Commissioner's Office. Archived from the original on 6 January 2015. Retrieved 8 February 2013.
  • ^ Data Protection Act 1998, Part IV (Exceptions – Crime and taxation), Section 29 Archived 1 June 2017 at the Wayback Machine
  • ^ Data Protection Act 1998, Part IV (Exemptions – Disclosures required by law or made in connection with legal proceedings etc.), Section 35 Archived 23 May 2017 at the Wayback Machine
  • ^ a b Data Protection Act 1998, Part III (Notification by Data Controllers), Section 21 Archived 7 December 2009 at the Wayback Machine, Office of Public Sector Information)
  • ^ Data Protection Act 1998, Part III (Notification by Data Controllers), Section 25 Archived 4 February 2013 at the Wayback Machine
  • ^ Data Protection Act 1998, Part VI (Miscellaneous and General), Section 55 Archived 24 August 2007 at the Wayback Machine, Office of Public Sector Information, accessed 14 September 2007
  • ^ Data Protection Act 1998, Part VI (Miscellaneous and General), Section 56 Archived 24 August 2007 at the Wayback Machine, Office of Public Sector Information, accessed 14 September 2007
  • ^ "Forced data subject access requests are now a criminal offence". Lewis Silkin. Archived from the original on 19 March 2015. Retrieved 10 March 2015.
  • ^ Bainbridge, D: "Introduction to Computer Law – Fifth Edition", p. 430. Pearson Education Limited, 2005
  • ^ Data Protection myths and realities, Information Commissioner's Office, accessed 30 August 2008
  • ^ Iversen, Amy; Liddell, Kathleen; Fear, Nicola; Hotopf, Matthew; Wessely, Simon (19 January 2006). "Consent, confidentiality, and the Data Protection Act". BMJ. 332 (7534): 165–169. doi:10.1136/bmj.332.7534.165. ISSN 0959-8138. PMC 1336771. PMID 16424496.
  • ^ "Data Protection Act 1998". UK Statute Law Database. Archived from the original on 20 August 2012. Retrieved 20 August 2012.
  • ^ a b "Your right of access". Information Commissioner's Office. Archived from the original on 26 May 2018. Retrieved 25 May 2018.
  • ^ "The Guide to Data Protection". Information Commissioner's Office. Retrieved 6 January 2015.
  • ^ Guidance – The Data Protection Act, Page of Assorted Guidance[permanent dead link], Information Commissioner's Office, accessed 20 October 2007
  • ^ "Guide to the General Data Protection Regulation (GDPR)". ico.org.uk. 22 December 2017. Archived from the original on 7 January 2018. Retrieved 6 January 2018.
  • [edit]

    UK legislation

    [edit]
    Retrieved from "https://en.wikipedia.org/w/index.php?title=Data_Protection_Act_1998&oldid=1223101018"

    Categories: 
    Data laws of the United Kingdom
    Data protection
    Information privacy
    United Kingdom Acts of Parliament 1998
    Hidden categories: 
    Webarchive template wayback links
    All articles with dead external links
    Articles with dead external links from December 2018
    Articles with permanently dead external links
    Use dmy dates from March 2020
    Use British English from August 2021
    Articles with short description
    Short description is different from Wikidata
    All articles with unsourced statements
    Articles with unsourced statements from November 2021
    CS1: long volume value
     



    This page was last edited on 9 May 2024, at 22:06 (UTC).

    Text is available under the Creative Commons Attribution-ShareAlike License 4.0; additional terms may apply. By using this site, you agree to the Terms of Use and Privacy Policy. Wikipedia® is a registered trademark of the Wikimedia Foundation, Inc., a non-profit organization.



    Privacy policy

    About Wikipedia

    Disclaimers

    Contact Wikipedia

    Code of Conduct

    Developers

    Statistics

    Cookie statement

    Mobile view



    Wikimedia Foundation
    Powered by MediaWiki