> For the complete documentation index, see [llms.txt](https://106-sam.gitbook.io/ejptv2-notes/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://106-sam.gitbook.io/ejptv2-notes/crto/law-and-compliance/data-protection-act.md).

# Data Protection Act

The Data Protection Act 2018 and the UK GDPR, protect individuals regarding the processing of their personal data. Controllers define the purposes and means of processing data, and Processors handle data based on the documented instructions of a Controller.\
\
There are 7 key data protection principles that the GDPR conveys:&#x20;

* **Lawfulness, fairness, and transparency**
  * **Lawfulness** means that the processing of personal data must have a valid legal basis under the GDPR, and be compliant with its requirements.
  * **Fairness** means that any processing of data must be fair towards the individual, and not unduly misleading or deceptive.&#x20;
  * **Transparency** means that controllers must provide individuals with Information regarding the processing of their data in a format that is concise and easy to understand. This should be done is collected and again whenever changes to the processing are made.

* **Purpose Limitation**

  \
  Data must be collected for specific and legitimate purposes, which are described at the time of collection, and must not be processed for any other reason.

* **Data Minimisation**

Controllers may only collect and process data that is relevant and limited to what is necessary for the intended purposes. They should not collect unnecessary personal data.

* **Accuracy**
  * Data must be accurate and, where necessary, kept-up-to-date. Controllers must take every reasonable step to ensure inaccurate personal data is deleted or rectified.

&#x20;

* **Storage Limitation**

  * Personal data must be processed in a manner that ensures the appropriate level of security, including protection against unauthorised processing, accidental loss, destruction, or damage. The GDPR does not specify what security measures should be implemented, so controllers must determine the most appropriate measures under the circumstance.

  &#x20;
* **Accountability** \
  Controllers and processors are responsible for, and must be able to demonstrate compliance with, all the aforementioned data protection principles.

A client may employ red team services as part of their fulfilment of GDPR Article 32, which states, "the controller and the processor shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk" . In cases where security testing is carried out against systems containing personal data that falls under the scope of GDPR, the testing itself must also be conducted in a manner that complies with the GDPR. Data Processing Agreements should be put in place by the client which stipulates the guidelines that should be followed for handling the data appropriately.\
\
The GDPR also applies to all organisations that store or process the personal data of EU residents, even if the organisation operates outside the EU.
