Chapter 6
Some legal obligations
1 Sources of law
We now come to the part of the syllabus which deals with law, and we start by looking at sources of law.
For countries in the European Union, European Union law will often supersede or overrule national law. European Union law can come into effect in two ways:
First, through regulations. If the European Union passes that regulation it immediately becomes directly applicable to all member states. They do not have to pass their own similar laws.
Secondly, the European Union can make directives, which are instructions to national governments to pass their own national laws to be in line with the directive. Normally governments are given a time period in which this legislation can be put forward and passed.
Most modern laws are legislation or statute, where they are written and passed by European or domestic parliaments. However, in some countries, particularly the United States and the United Kingdom, there is a very strong tradition of case law. Case law can come from the very ancient common law or equity, and often depends on the idea of precedent. Precedent means that if the case has been decided in a higher court then in the future lower courts must follow the precedent or example set by the higher court.
Case law does not overrule any type of statute law but even with tightly worded statute law an interpretation problems can exist and cases can be looked at to shed light upon interpretation and how the laws should be applied.
2 Data Protection Act
Many jurisdictions have laws protecting their population from misuse and exploitation of personal data. In the European Union, this is achieved through the General Data Protection Regulation which, in the UK, has been implemented in the Data Protection Act 2018.
The Data Protection Act in the UK relates to personal data ie data relating living people who can be identified from the information and which is processed wholly or partly automatically. We are not talking here about data relating to companies: we are talking about data relating to people.
2.1 The act sets out certain principles:
For data-protection questions, identify whether the statement is about a legal principle, an individual right, or a security risk/control. Do not assume that a useful control is itself a data-protection principle.
Data shall be processed fairly and lawfully.
It can only be obtained for one or more specified and lawful purposes.
It must not be excessive to what’s required.
It must be accurate and kept up-to-date.
It must not be kept for longer than necessary.
IT must be held and processed securely.
The data subject is a person about whom the data is held and that person has certain rights:
The right to be informed about the information being held.
The right to access the data.
The right to have the data rectified and corrected.
The right to have the data erased (for example, if it is being held without good reason).
The right to restrict processing. This is a limited right which might mean that data can be held but not processed or used.
The right to data portability. Individuals have the right to obtain and reuse their data for their own purposes.
The right to object. For example, to object to data being used for direct marketing.
Rights relating to automated decision-making and profiling.
There are special rules dealing with data held by the police and security services. You cannot, for example, insist that the government erases your criminal record, nor do you have a right to access data the security services might hold about you.
The GDPR restricts the transfer of data outside the European Economic Area (where the GDPR applies) unless the rights of individuals are protected in some other way.
3 Risks to data
3.1 Data can be subject to a number of risks.
Human error. For example, someone deletes an important file or important information or indeed leaves a disk on the bus going home.
Technical problems. Hard disks can crash and data can be lost.
Catastrophic events would include events such as a fire or a flood destroying computers and the data they hold.
Malicious damage occasionally occurs. Sometimes this is done by an employee who is unhappy or who has been sacked. Sometimes it is done by hackers, people from outside the organisation who infiltrate the organisation’s data and change or steal it.
Industrial espionage or sabotage. Rivals obtain any data for their own purpose or deleting your data to put you at a disadvantage.
Dishonesty or fraud. For example, illegally causing cash to be transferred, goods to be delivered, receivables to be written off.
Organisations must try to safeguard their data. Not only can lost or stolen data cause financial loss and loss of reputation, but it can also in some cases leave them open to prosecution.
Some legal obligations (incl. data protection)
5 questionsAnswer the questions one at a time. Your progress is saved so you can leave and come back.
Open chapter practice

