The purpose of data protection legislation is to ensure that personal data is not processed without the knowledge and, except in certain cases, the consent of the data subject, to ensure that personal data which is processed is accurate, and to enforce a set of standards for the processing of such information.
Concerns exist wherever personally identifiable information is collected and stored - in digital form or otherwise. Improper or non-existent disclosure control can be the root cause for privacy issues.
If your business requires you to store people’s personal details, such as customer or employee records, then you must comply with the Data Protection Act 1998.
BSI offers a range of standards, publications and training designed to ensure your business complies with the Act.


Data Protection Guide
This guide will provide you with guidance for the implementation of the Data Protection Act (DPA) itself and it also covers areas such as email policy, database management, subject access and e-commerce.
Data protection training