Data Protection Help! Sheet
The Data Protection Act 1998 aims to strike a balance between the rights of individuals and the interests of those with legitimate reasons for using personal information. Individuals, for example, are given the rights to access certain information held on them.
The Management Committee needs to ensure that the organisation has considered 3 key questions in order to ensure that they are compliant with the Act:
1. Does your organisation process personal information?
Personal information means data which relates to a living individual who can be identified from those data (or from that data and other information which is in the organisation’s possession). It covers both facts and opinions about the individual.
2. Are we obliged to notify the Information Commissioner’s Office that we are handling personal information?
The Data Protection Act 1998 obliges those who process personal information to notify the Information Commissioners Office that they are doing so. However, most not for profit organisations will find themselves covered by the exemptions for this.
Essentially, if you are a not for profit organisation processing personal information solely for:
then you are likely to find yourself exempt from notification. In addition, if none of your processing is carried out on a computer, then you are unlikely to need to notify, but you do need to check the detail in the Information Commissioner’s online guidance at www.ico.gov.uk.
Click here for a quick self-assessment questionnaire to confirm whether your organisation needs to provide notification.
3. What principles should govern how we handle personal information and how are we ensuring that our policies and practices are compliant?
Whether or not you are required to provide notification that you are handling personal information, your organisation’s policies and practices must still comply with eight enforceable principles of good information handling practice.
These say that data must be:
For personal information to be considered fairly processed, at least one of the several extra conditions must be met. These include:
Additional conditions relate to sensitive personal information such as racial or ethnic origin, political opinions, trade union membership or physical or mental health conditions.
Further guidance:
Key contact:
Information Commissioner – guidance on storage of personal information, legal requirements, rights of individuals, etc. Tel: 028 9051 1378. Helpline: 01625 545 745 Website: www.informationcommissioner.gov.uk
Download the following user friendly guides:
Data Protection Act Factsheet
Notification Exemptions: A Self Assessment Guide
NICVA | 61 Duncairn Gardens | Belfast | BT15 2GB
Northern Ireland Council for Voluntary Action is registered as a company limited by guarantee in Northern Ireland (No 1792) and is registered as a charity for tax purposes with the Inland Revenue
- Volunteers and Expenses
- Volunteer Drivers
- Volunteers and the Law
- Volunteers and Insurance
- NICVA Advice Note 9: Lotteries
- NICVA Advice Note 10: Collections
- NICVA Advice Note 12: Insurance
- Data Protection Notification Exemptions: A Self Assessment Guide
- Data Protection Act Factsheet
- Employment: Where to go
- Legal Structures And Charitable Status
- Managing Staff & Volunteers
- Understanding Your Governing Document
- What Is A Charity?
- Managing Risk
- What Is Liability?
Labour Relations Agency
Comprehensive information, advice, downloadable publications and free training on employment practice.
Inland Revenue
Information on tax, PAYE and charities.
Institute of Fundraising
Provides codes of good practice.
Volunteer Development Agency
Guidance on legal issues and good practice relating to child protection and volunteers.
More useful links