
Data Protection
How we process and handle personal data by complying with the law, including information sharing.
What is data protection
Data protection refers to the legal and regulatory framework that governs how personal data is collected, used, stored, and shared by organisations, businesses, and the public sector. Its main goal is to protect individuals' privacy and ensure their personal information is handled responsibly.
There are two key pieces of legislation that govern data protection in the UK:
- UK General Data Protection Regulation (UK GDPR), adapted from EU GDPR after Brexit
- Data Protection Act 2018, this legislation supplements the UK GDPR and provides specific rules and exceptions for areas like law enforcement and national security
Main principles
The UK GDPR states that personal data must be:
- processed lawfully, fairly and in a transparent manner
- purpose limited - collected only for specified, explicit and legitimate purposes
- data minimisation - adequate, relevant and limited to what is necessary
- accuracy - accurate and kept up to date
- storage limitation - held only for the absolute time necessary and no longer
- integrity and confidentiality - processed in a manner that ensures appropriate security of the personal data
For more information on the UK GDPR visit .