University Policy on Data Protection

The primary purpose of current data protection legislation is to protect individuals against possible misuse of information about them held by others. It is the policy of the University to ensure that all members of the University and its staff are aware of the requirements of data protection legislation in relation to their individual responsibilities.

The Act covers personal data, whether held on computer or in certain manual files.

The University is obliged to abide by the data protection principles embodied in the Act. These principles require that personal data shall:

  1. be processed fairly and lawfully;
  2. be held only for specified purposes and not used or disclosed in any way incompatible with those purposes;
  3. be adequate, relevant and not excessive;
  4. be accurate and kept up-to-date;
  5. not be kept for longer than necessary for the particular purpose;
  6. be processed in accordance with data subject's rights;
  7. be kept secure;
  8. not be transferred outside the European Economic Area unless the recipient country ensures an adequate level of protection.

Definitions and guidance on these principles may be found here.

The Act provides individuals with rights in connection with personal data held about them. It provides individuals with the right to access data concerning themselves (subject to the rights of third parties). It also includes the right to seek compensation through the courts for damages and distress suffered by reason of inaccuracy or the unauthorised destruction or wrongful disclosure of data. Information on how to make a request for access to personal data under the Act may be obtained from data.protection@admin.ox.ac.uk.

Under the terms of the Act, the processing of data includes any activity to do with the data involved. All staff or other individuals who have access to, or who use, personal data, have a responsibility to exercise care in the treatment of that data and to ensure that such information is not disclosed to any unauthorised person. Examples of data include address lists and contact details as well as individual files. Any processing of such information must be done in accordance with the principles outlined above. In order to comply with the first principle (fair and lawful processing), at least one of the following conditions must be met:

  • the individual has given his or her consent to the processing;
  • the processing is necessary for the performance of a contract with the individual;
  • processing is required under a legal obligation;
  • processing is necessary to protect the vital interests of the individual;
  • processing is necessary to carry out public functions;
  • processing is necessary in order to pursue the legitimate interests of the controller or third parties (unless it could prejudice the interests of the individual).

In the case of sensitive personal data, which includes information about racial or ethnic origins; political beliefs; religious or other beliefs; trade union membership; health; sex life; criminal allegations, proceedings or convictions, there are additional restrictions and explicit consent will normally be required.

In relation to security (Principle 7), the Data Controller (the University) must take appropriate technical and organisational measures against unauthorised or unlawful processing of personal data and against accidental loss or destruction of or damage to personal data. Staff and other individuals should be aware that guidelines and regulations relating to the security of manual filing systems and the preservation of secure passwords for access to relevant data held on computer should be strictly observed.

Staff should also note that personal data should not normally be provided to parties external to the University. Special arrangements apply to the exchange of data between the University and the colleges. For further guidance on this, please contact data.protection@admin.ox.ac.uk.

Under Principle 8, which restricts the transfer of material outside the European Economic Area, personal data about an individual placed on the world wide web is likely to breach the provisions of the Act unless the individual whose data is used has given his or her express consent. It is important that all those preparing web pages, address lists and the like, are aware of these provisions, and seek advice from the Information Compliance Team if in doubt.

The Act specifies arrangements for the notification of processing undertaken by the Institution. The University has a wide ranging notification under the 1998 Act, which can be accessed online. Any members of staff who are uncertain as to whether their activities or proposed activities are included in the University's notification should contact the Information Compliance Team in the first instance.

A failure to comply with the provisions of the Act may render the University, or in certain circumstances the individuals involved, liable to prosecution as well as giving rise to civil liabilities. Individuals are encouraged to familiarise themselves with the general aspects of Data Protection contained in the University's guidance to the Act, referred to above and with any specific measures recommended by the University or their Department relevant to the particular nature of their work. Further information and advice may be obtained from the Information Compliance Team.