|
The principles are that personal information shall be:
- Fairly and lawfully processed (in particular that the individual whose information it is has consented to the processing of his/her personal information)
- Processed for limited purposes (only for the purposes for which it was originally supplied. University departments receiving personal information from individuals are obliged to ensure such individuals are fully aware of what we will use this information for. Staff should NOT assume that the provision of personal information gives the University the right to use that information for any purpose).
- Adequate, relevant and not excessive
- Accurate and up to date
- Not kept longer than is necessary (personal information should only be retained by the University for as long as is required to fulfill the purposes for which it was originally provided. Beyond this point it should be securely destroyed. Please see the University's retention schedule for guidelines on how long certain types of information should be kept).
- Processed in accordance with the data subjects' rights (not to do anything with the information which would prejudice the rights of the individual in any way).
- Secure (from the point at which personal information is received until the point at which it is destroyed, such information must be processed securely. University departments are obliged to ensure they have appropriate mechanisms in place to ensure adequate security for the storage and transmission of all electronic and paper records containing personal information, particularly more sensitive personal information. Advice on how to process electronic information securely can be found at at the University's website on Information Security or by contacting the Senior Assistant Registrar for Information Security, Risk Management and Business Continuity, Ros Roke, at R.L.Roke@warwick.ac.uk or on extension 51270. BE AWARE that the loss, disclosure or unplanned destruction of personal information can lead to legal action being taken against the University).
- Not transferred to a country or a territory outside the European Economic Area (EEA) unless that country or territory ensures an adequate level of protection (if you need to transfer data in this way, please consult the Administrative Officer for Legal Compliance at alison.thompson@warwick.ac.uk who can offer advice).
|
Staff, students and members of the University must comply with the eight data protection principles.