Section 34 | Overview and general duty of controller
From legislation.gov.uk
(1)This Chapter sets out the six data protection principles as follows—
(a) sets out the first data protection principle (requirement that processing be lawful and fair);
(b) sets out the second data protection principle (requirement that purposes of processing be specified, explicit and legitimate);
(c) sets out the third data protection principle (requirement that personal data be adequate, relevant and not excessive);
(d) sets out the fourth data protection principle (requirement that personal data be accurate and kept up to date);
(e) sets out the fifth data protection principle (requirement that personal data be kept for no longer than is necessary);
(f) sets out the sixth data protection principle (requirement that personal data be processed in a secure manner).
(2)In addition—
(a)each of sections , , and makes provision to supplement the principle to which it relates, and
(b)sections and make provision about the safeguards that apply in relation to certain types of processing.
(3)The controller in relation to personal data is responsible for, and must be able to demonstrate, compliance with this Chapter.