Data Protection Act 2018UK · 2018 c. 12
Digiphile
Chapters

Chapter 4Controller and processor

In Part 4 – Intelligence services processing

  • Section 101Overview

    This Chapter sets out— (a) the general obligations of controllers and processors (see sections 102 to 106 ); (b) specific obligations of controllers and processors with respect to…

  • Section 102General obligations of the controller

    Each controller must implement appropriate measures— (a) to ensure, and (b) to be able to demonstrate, in particular to the Commission, that the processing of personal data complies…

  • Section 103Data protection by design

    (1) Where a controller proposes that a particular type of processing of personal data be carried out by or on behalf of the controller, the controller must, prior…

  • Section 104Joint controllers

    (1) Where two or more controllers jointly determine the purposes and means of processing personal data, they are joint controllers for the purposes of this Part. (2) Joint…

  • Section 105Processors

    (1) This section applies to the use by a controller of a processor to carry out processing of personal data on behalf of the controller. (2) The controller…

  • Section 106Processing under the authority of the controller or processor

    A processor, and any person acting under the authority of a controller or processor, who has access to personal data may not process the data except— (a) on…

  • Section 107Security of processing

    (1) Each controller and each processor must implement security measures appropriate to the risks arising from the processing of personal data. (2) In the case of automated processing,…

  • Section 108Communication of a personal data breach

    (1) If a controller becomes aware of a serious personal data breach in relation to personal data for which the controller is responsible, the controller must notify the…