The Data Protection Act 1998 is a piece of legislation designed to safeguard details relating to living people. It controls what organisations are allowed to find out about you, limits how they store and process this knowledge, and gives you the right to inspect your details and to correct them if they are wrong.
Data Protection Principles
The Data Protection Act sets out eight principles that form its basis. In basic terms, these principles are as follows, each relating to personal data:
- It shall be processed in a fair way.
- The purpose for which it was obtained shall be specified, and it shall not be processed for some other purpose.
- It shall be adequate and relevant, and not excessive for its purpose.
- It shall be accurate and kept up to date.
- It shall not be kept for longer than is necessary.
- Subjects have the right to access and correct what is held about them.
- Appropriate technical and organisational measures shall be put in place to protect it.
- It shall not be transferred to a country outside the European Economic Area unless that country has adequate laws of its own.

Describe what your employer is monitoring or asking for and find out whether it is lawful under UK privacy and data protection law.
Try our Workplace Privacy Checker free, here on this site →What Is Personal Data?
The protection principles apply to personal data. So, what is it?
In short, it is anything that can be used to identify a living person. This includes both information directly stored with an individual’s credentials, and more loosely bound records that could be matched up with an individual by subsequent processing.
Such personal data includes, but is not limited to, the following:
- names
- addresses
- dates of birth
- telephone numbers
- email addresses
- religion
- race
- political allegiance
- medical history
Except for some specific exceptions, the Act relates to records held on computers.
Your situation may be slightly different. ask a question below ↓ and our editorial team will reply with our advice.
Your Rights
Under this legislation, you have the following rights:
- to gain access to computerised records about you and to some manual records
- to correct, block, remove or destroy inaccurate records
- to ask a data controller not to process information if that processing could cause you “substantial unwarranted damage or distress” (although they are not always bound to comply with such requests)
- to request that your details not be used for unsolicited direct marketing
- to object to automatic decisions made without human involvement and based on your data
- to ask the Information Commissioner’s Office to investigate a perceived breach, and the right to claim compensation for damage, and possibly distress, if one is found to have taken place
Applications of the Act in your Workplace
There are two main reasons why you should make sure you understand the basics of this law. First, it applies directly to you. Your employer holds information about you, and it is in your own interests to ensure that they are complying with this legislation. This will ensure that the data they hold on you is not excessive, but is correct and is kept confidential. A second consideration is that if you are handling other people’s records you have a responsibility to treat their privacy with respect, and to comply with this law. By doing this, you keep your company’s customers happy and protect yourself and your employer from the threat of legal action.
*The EU General Data Protection Regulation (GDPR) superseded the UK Data Protection Act 1998 on May 25, 2018. Following Brexit, the UK implemented the UK GDPR alongside the Data Protection Act 2018, which came into effect on January 1, 2021. These policies expand the rights of individuals to control how their personal data is collected and processed and place a range of new obligations on organisations to be more accountable for data protection.
Organisations are obliged to have technical and procedural measures in place to safeguard the personal information they hold.
I came in this morning (there is another way of getting into the building that avoids the door with the new lock). A couple of hours later the building manager comes in and asks me if I got the key. I asked her what she was talking about and she informed me that a member of staff got my address and was coming to my door to give me the key. I have since found out they phoned my line manager who willingly gave them my address (which luckily turned out to be incorrect) without my permission but informed them that she would contact me. I had no attempt of contact from my manager yesterday to tell me this.
Where do I stand with this? I am an extremely private person who has had to create boundaries with my work previous but now both my number and address have been used by people I do not know. Help!
Can managers give access of another employee to another subordinate just because they also have the manager title ?
Does this constitute a breach of data.
Can my employer share my address with a line manager as I have had a line manger come to my house to call me into work as I’m flexi furlough and my mobile was switched off does this breach GDPR
On my eife work place
Som one ar send privet personal information to somone
Wat shuld we do now..
My boss also sent my personal mobile number to my colleagues without my consent prior to letting me go, is this allowed?
Ask Employee Privacy Rights a question
Ask our editorial team a question and we will reply with our advice. Tell us as much about your situation as you can: the more detail you give, the more useful our answer can be.
You do not need to use your real name. Please do not include your full address, phone number, email address, or the names of other people. We may edit or remove identifying details for privacy and legal reasons.
Comments are moderated before publication.