Skip to content
Solved
ConnectSearchBrowseDocs
Sign in

Contents

Legislation
Data Protection Act 2018

Crossheading General obligations

  • Section 56 General obligations of the controller
  • Section 57 Data protection by design and default
  • Section 58 Joint controllers
  • Section 59 Processors
  • Section 60 Processing under the authority of the controller or processor
  • Section 61 Records of processing activities
  • Section 62 Logging
  • Section 63 Co-operation with the Commissioner
  • Section 64 Data protection impact assessment
  • Section 65 Prior consultation with the Commissioner
  1. General obligations
  2. Data protection by design and default

Section 57 | Data protection by design and default

From legislation.gov.uk

(1)Each controller must implement appropriate technical and organisational measures which are designed—

(a)to implement the data protection principles in an effective manner, and

(b)to integrate into the processing itself the safeguards necessary for that purpose.

(2)The duty under subsection (1) applies both at the time of the determination of the means of processing the data and at the time of the processing itself.

(3)Each controller must implement appropriate technical and organisational measures for ensuring that, by default, only personal data which is necessary for each specific purpose of the processing is processed.

(4)The duty under subsection (3) applies to—

(a)the amount of personal data collected,

(b)the extent of its processing,

(c)the period of its storage, and

(d)its accessibility.

(5)In particular, the measures implemented to comply with the duty under subsection (3) must ensure that, by default, personal data is not made accessible to an indefinite number of people without an individual's intervention.

PreviousNext
PrivacyTerms