Core Principles of Data Protection

And the rights of individuals 

Core Principles of Data Protection 
Data must be processed lawfully, fairly and in a transparent manner
Data must be collected for specified, explicit and legitimate purposes
The data collected must be adequate, relevant and limited to what is needed
Data should be accurate, and where necessary, kept up to date
Data is kept no longer than necessary for the processing
Data must be processed in a manner that ensures appropriate security by technical and organisational measures


The Rights of Individuals
To be informed
To access
To rectification
The right to object to processing
The right to restrict processing
The right to erasure or the right to be forgotten
The right to data portability
Rights in relation to automated decision making and profiling
Electronic vs. Paper copies

Electronic vs. Paper copies

Should you keep both electronic and paper records of some important data? In light of the ever increasing number of cyber attacks on the education sector, and the advice given by the NCSC,  we at DPO For Education continue to advise our clients to keep both electronic...

Appointing a Data Protection Officer

Appointing a Data Protection Officer

A simple guide to understand the role of a DPO in schools and who is and who is not suitable for the role. Whatever the size and setting of your school, the GDPR (General Data Protection Regulation) places high expectations on you to protect the personal data in your...

GDPR DOs & DONT’S Infographic

GDPR DOs & DONT’S Infographic

Training and Awareness is a way to inform your staff that data protection is everyone’s responsibility and that small steps to protect data can make a big difference. Print this poster to display in the staff room and offices. Poster: GDPR - Data Protection Dos and...