The two main guiding principles are:
- Transparency – it should be clear why personal information is being held and for what purpose it will be used for.
- Consent – individuals must give consent to the information being collected and have the chance to opt out of further uses of their personal information eg marketing.
Individuals have the right to access information held about them and request a copy of the information you keep. They also have the right to know how the information is being processed and to whom it may be disclosed. Businesses are allowed to charge up to £10 for providing the information requested.
All information must be provided within a statutory time scale – 40 calendar days or you’ll be in breach of the Data Protection Act.