An organisation holding personal data who determines the purposes for which, and the manner in which, it is to be processed. In some circumstances it could be a person, and the processing may be carried out jointly or in common with other data controllers. The University is a data controller for the personal data it holds.
An organisation (or in some circumstances it could be a person) who processes personal information on a data controller's behalf. For example, outsourcing the disposal of confidential waste to an external company - that company is a data processor.
A living individual who can be identified from personal data.
Disclosing can take the form of paper documents, viewing of a screen, telling someone the content of records, playing audiotapes - anything that passes personal data to another person.
Notification is the process by which a data controller's processing details are added to a the register of data controllers held by the Information Commissioner's Office. Under the Act, every data controller processing personal information needs to notify unless they are exempt. Failure to notify is a criminal offence. Even if a data controller is exempt from notification, they must still comply with the data protection principles.
Personal data means information about a living individual who can be identified from that information and other information which is in, or likely to come into, the data controller's possession.
Processing means obtaining, recording or holding the data or carrying out any operation or set of operations on data. This includes collecting, recording, amending, destroying, disclosing, rearranging and extracting information by any means.
Sensitive data means data containing any of the following information:
While financial information is not classified as sensitive data under the Act, it should be afforded a similar level of security given the damage that could be caused to an individual if it were to be accessed without authorisation.