Initially the Data Protection Act (DPA) (1998) was an act of parliament that was passed to protect all personal data stored on computers or organised filing systems, especially in large organisations such as Exxon and Google. This replaced the Data protection act 1984, which gave a brief touch on digital media and computers. DPA (1998) was superseded by the 2018 DPA enforcing our online data, which is tracked at every purchase and post you make, to be further transparent on your data and more liable for data breaches that have become more likely. All of the DPA’s were passed to lay the groundwork for UK law on how organisations and businesses store, process and protect personal information. Making your data more safe online.
Today, the digital world is ever expanding. Data is absorbed at every corner of the internet and stored on servers without your acknowledgement. Due to this the government has had to ensure that your data is safe, stays safe and that it is processed ethically and correctly. The Data Protection Act (2018) plays a predominant role in how a vast number of sized organisations can use and handle your data. The purpose of the DPA (2018) is to make you feel that you’re in control of your data as well as hold companies accountable for any misuse of data, ensuring that your data is safe and protected.
The DPA covers any information that could be used to identify you, this could be your name, address or bank information. For the majority of businesses this means their customer data, which is collected in checkouts and cookies (a small text file containing letters and numbers that a website stores on your computer or device to remember information about your visit), has to be done in line with the DPA. However, the DPA also covers any and all data collected by a third party data source or in email signups.
It’s been seen before, with a number of companies breaching the DPA, such as the NHS, GP practices and Morrisons. Between June and December of 2019, NHS worker Christopher O’Brian had successfully accessed the medical records of 14 patients at South Warwickshire NHS trust foundation. O’Brian had personally known the victims and he accessed their health records without permission from the trust’s authority for a valid business reason. Therefore, a breach of the DPA (2018) under s.170(1) in which it is an offence for a person to obtain personal data without the controller’s permission. Unfortunately, the Information Commissioner’s Office (ICO) is unable to provide compensation for those affected. However, they have applied for them to claim compensation. O’Brian is set to pay £3000 (£250 to 12 victims).
This example is important to remind people that they need to be vigilant about how staff, of any company, handle sensitive information as well as reminding those who have control over sensitive data to handle it in a sensible and legal manner.
The DPA is a necessary piece of legislation for data protection. Allowing for companies to collect data safely and customers to be kept safe from mistakes and malicious intentions. Although many cases have uprose, signifying that perhaps security of the data itself needs to be pushed.
By Michael Brennan, a student at the Island VI Form.


