16.Data_Controllers.pdf

(24 KB) Pobierz
Any person who controls
the content and use of
personal data
Any person who determines the
purposes and manner by which
any personal data is processed
To obtain and process information fairly
Obligations imposed upon
data controllers
(required to
disclose the following to the
data subject)
The identity of the data controller
A Data Controller must be a person
recognised by law, so it can be either
the natural person, on organisation or
a body corporate.
To keep information only for one or more
specified, explicit and lawful purposes
To use and disclose the information only in
ways compatible with these purposes
To keep personal data safe and secure
To keep personal data accurate,
complete and up-to-date
To ensure that personal data is
adequate, relevant and not excessive
The reason the data is gathered
Data
Controllers
Data Security Breach
Code of Practice
Principles data
controllers are required
to comply with
Any other reasonable information that
the data subject may require
Requires the data
controllers to inform the
ODPC where there is a
breach in the control of
personal data.
To retain personal data for no longer
that is necessary for the purpose for
which it was obtained
To give a copy of personal data
to an individual, on request
Data controllers are required
to maintain a record of each
breach of personal data.
The data controller must
report the breach within two
working days of becoming
aware of the incident.
Depending on the severity of
the breach, this reporting
obligation may be extended to
data subjects and others.
Zgłoś jeśli naruszono regulamin