LO4 - 4.1 UK Legislation AAI side Flashcards
What are the 6 principles of the data protection ACT
- Data must be collected lawfully and processed fairly
- Collected data must only be used for the reasons specified
- Data must be relevant and not excessive
- Data must be accurate and up-to-date
5.Data must not be stored for longer than necessary - Data must be stored and processed securely
Actions organisations must take to stick to the DPA
- Appoint a data protection officer
2.Strong security measure = physical or digital protection methods - Training staff
- People have the right to change their data if it is incorrect
5.People have a right to request their data
Computer misuse Act 1990
-Attempts to stop and punish those who use computers inappropriately
-Breaking this act could result in fines and a jail sentence if committed purposely
Main principles of the CMA 1990
- no unauthorised access to data
- no unauthorised access to data that could be used for further illegal activities
- no unauthorised modification of data
Freedom of information act 2000
-allows people to request public authorities to release information such a local councils
-formally submitted by letter or email
-reply is required withing 20 days
Regulation of investigatory powers act 2000 - RIPA
-used to monitor and access online communication of suspected criminals
-grants the following powers
encrypted data may be accessed
install surveillance to track online activity
Copyright, Designs and Patents Act 1988
-makes it a criminal offence to copy work that is not your own without the permission of creator
-prohibits = making copies of copyright material
importing and downloading illegally copied material
Information commissioners office (ICO) codes of practice
-is senior government in charge of countrys freedom of information requests and protection of personal data
- publishes codes of practice about various data protection and privacy topics
Protection of Freedoms Act 2012
- states how biometric data is stored, handled and collected
- creates new regulations for CCTV and ANPR (automatic number plate recognition)
- Disclosure and barring service (dbs) was created to run background checks
- extends freedom of information act 2000
Privacy and electronic communications regulations 2003 - updated in 2011
-offence to directly contact an individual unless they have opted to receive communication
- companies clearly state who they are when contacting customers
-must explain how cookies are used on their website
-only contact customers through communication channels
Equality Act 2010
-legally protects people from discrimination in the workplace and wider society
-protected characteristics
-aim to end discrimination