The Data Protection Act 1998 Definitions

Information Commissioner

Formerly known as the Data Protection Commissioner, the Information Commissioner is an independent officer who is appointed by Her Majesty the Queen and who reports directly to Parliament. The Commissioner's duties are to :

  • Promote the following of good practice by data controllers and , in particular, promote the observance of the requirements of the Act by data controllers,
  • Spread information on the Act and how it works, and
  • Encourage, where appropriate, the development of Codes of Practice for guidance as to good practice.

Requests for Assessment are also made to the Commissioner by any persons who is, or believes themselves to be, directly affected by any processing of personal data.

Data Controller

Means a person who (either alone or jointly or in common with other persons) determines the purposes for which and the manner in which any personal data are, or are to be processed. This includes determination of what non-automated (manual data) is covered by the Act.

Data Subject

Means an individual who is the subject of personal data.

Data

Means information which is :

  1. Being processed by means of equipment operating automatically in response to instructions given for that purpose,
  2. Recorded with the intention that it should be processed by means of such equipment,
  3. Recorded as part (or with the intention that it should form part)  of a relevant filing system (i.e. any set of information relating to individuals to the extent that, although not processed as in (1) above, the set is structured, either by reference to individuals or by reference to criteria relating to individuals, in such a way that specific information relating to a particular individual is readily accessible), or
  4. Does not fall within paragraph (1), (2) or (3) but forms part of an accessible record [which is defined in Section 68 of the Act and which can be summarised here as a health record, educational record (LEA schools and special schools only), local authority housing record or local authority social services record - N.B. data forming part of an accessible record may fall within paragraphs (1), (2), (3) or (4) of the definition of data].

From the above definition it is clear that the act is now concerned not only with automatically processed or processable information but also data falling within the definition of 'relevant filing system' as defined in paragraph (3) above and which is often referred to as 'manual data'.

Relevant Filing System

This term means 'any set of information relating to individuals to the extent that, although the information is not processed by means of equipment operating automatically in response to instructions given for that purpose, the set is structured, either by reference to individuals or by reference to criteria relating to individuals, in such a way that specific information relating to a particular individual is readily accessible'.

This definition derives from the term 'personal data filing system' in the Directive which is defined as :

'any structured set of personal data which are accessible according to specific criteria, whether centralised, decentralised or dispersed on a functional
or geographical basis'.

The Directive limits this definition by stating that the scope of protection of individuals does not cover 'unstructured files'.

Personal data

Means data which relate to a living individual who can be identified :

  • From these data, or
  • From those data and other information which is in the possession of or is likely to come into the possession of, the data controller,

and includes any expression of opinion about the individual and any indication of the intentions of the data controller or any other person in respect of the individual.

Processing

In relation to information or data, means obtaining, recording or holding the information or data (which included, in relation to personal data, obtaining or recording the information to be contained in the data) or carrying out any operation or set of operations on the information or data, including :

  • Organisation, adaptation or alteration of the information or data,
  • Retrieval, consultation or use of the information or data (which, in relation to personal data, includes using the information contained in the data),
  • Disclosure of the information or data (which, in relation to personal data, includes disclosing the information contained in the data) by transmission, dissemination or otherwise making available, or
  • Alignment, combination, blocking, erasure or destruction of the information or data.

Data Processor

In relation to personal data, means any person (other than an employee of the data controller) who processes the data on behalf of the data controller. e.g. a computer bureau

Recipient

In relation to personal data, means any person to whom the data are disclosed, including any person (such as an employee or agent of the data controller, a data processor or an employee or agent of the data processor) to whom they are disclosed in the course of processing the data for the data controller, but does not include any person to whom disclosure is or may be made as a result of, or with a view to, a particular inquiry by or on behalf of that person made in the exercise of any power conferred by law.

Third Party

In relation to personal data, means any person other than :

  • The data subject,
  • The data controller, or
  • Any data processor or other person authorised to process data for the data controller.

Notification

This replaces the previous Data Protection Register.