University Secretary

View the answers

What are the eight Principles of the Act?

The eight principles state that:

a) personal data shall be processed fairly and lawfully

b) personal data shall only be obtained for specified purposes and not processed for any other purposes

c) the amount and type of personal data held shall be adequate, relevant and not excessive for the purpose(s) for which it is processed

d) personal data shall be accurate and kept up to date

e) personal data shall not be kept for longer than is necessary

f) personal data shall be processed in accordance with the rights of data subjects under the Act

g) appropriate measures will be taken by the data controller against unauthorised or unlawful processing and against accidental loss of personal data

h) personal data shall not be transferred to a country outside the European Economic Area unless that country ensures an adequate level of protection for the rights and freedoms of data subjects in relation to processing personal data.