| |
The Data Protection Act (DPA) aims to promote high standards in the handling of personal information, and to protect the individual's right to privacy. The Data Protection Act (DPA) applies to anyone holding information about living individuals in electronic format and in some cases on paper. They must follow the eight data protection principles of good information handling.
Nova Risk Management is registered with the Information Commissioner No. Z6679635 and adopts the eight data protection principles.
 |
 |
 |
fairly and lawfully processed;
|
| |
 |
|
processed for specified purposes;
|
| |
 |
|
adequate, relevant and not excessive;
|
| |
 |
|
accurate; and where necessary, kept up to date;
|
| |
 |
|
not kept longer than necessary;
|
| |
 |
|
processed in line with the rights of the individual;
|
| |
 |
|
kept secure;
|
| |
 |
|
not transferred to countries outside the European Economic Area unless there is adequate protection for the information. |
Personal data covers both facts and opinions about an individual. It also includes information regarding the intentions of the data controller towards the individual, although in some limited circumstances exemptions will apply. |