Who do the Data Protection Acts apply to?
The Data Protection Acts set out the principles of data protection, which establish requirements in relation to the holding, use and disclosure of personal data. The Acts apply to all data controllers, which includes any person or corporate entity who/which stores or processes personal information relating to any living person. As such, the Data Protection Acts will apply to any person or Organisation which processes personal information related to an Employee (current or past) or applicant for employment.
Personal data
Personal data is defined as information from which the data subject may be identified. The Acts apply in respect of both paper and automated data. The legislation also sets additional requirements in relation to the collection, processing and storing of sensitive personal data.