Toggle menu

Data Protection Impact Assessment Policy

Appendix 1: (EU) General Data Protection Regulation 2016 - Principles

9.1

Personal data shall be processed fairly and in a transparent manner. (Transparency)

Personal data shall only be obtained only for specified explicit and legitimate purposes. (Purpose limitation)

Personal data shall be adequate, relevant and limited to what is necessary for the purpose. (Data minimisation)

Personal data shall be accurate and, where necessary, kept up to date, including necessary correction or erasure without delay. (Accuracy)

Personal data processed for any purpose or purposes shall not be kept for longer than is necessary in a form that permits identification. (Storage limitation)

Personal data shall be processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage. (Integrity and Confidentiality)

9.2 In addition to the above the data controller - Wiltshire Council, shall be responsible for, and be able to demonstrate compliance with the above principles.

9.3 Personal data shall be processed in accordance with the rights of data subjects under the GDPR which include the following:

Right to access information held.

Right to rectification of inaccurate data or completion of incomplete data.

Right to erasure in certain circumstances.

Right to restrict processing of personal data.

Right to data portability.

Right to object to processing.

 

 

 

 

Share this page

Share on Facebook Share on Twitter Share by email