Data Protection
August 29, 2025โข174 words
After Brexit, the UK developed its own version of the GDPR (originally created by the European Union) known as UK GDPR
๐ 7 core principles:
lawfulness, fairness and transparency: asking for consent; respecting a Privacy Policy; consent might not be necessary if use of data is enforced by law for specific reasons (eg. public or vital interest)
purpose limitation: only use the data if necessary and for a specific reason
data minimisation: only collect the minimum amount of data needed
accuracy: data must be correct, up to date and the user can request amendments
retention: the user can request for the data to be deleted at any moment (right to be forgotten)
integrity and confidentiality: the data must not be shared if not necessary or for purposes other than what was initially set out
accountability: the business storing the data is responsible for them, and must act to reduce the risk of breaches and comply with the law
๐ Resources