Data protection legislation includes the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and other laws relating to processing of personal information and privacy. It also includes relevant guidance issued by the Information Commissioner's Office (ICO).
The Act contains six data protection principles. Organisations that collect and use personal information must be able to show that they comply with these principles. This means personal data must be processed:
- lawfully, fairly and transparently
- for specified, explicit and legitimate purposes
- in a way that is adequate, relevant and limited to what is necessary
- accurately and kept up to date
- with the appropriate security and protection
- and kept only for as long as necessary.
Personal data shall not be transferred to countries that do not have an adequate level of data protection. All processing of personal data must be in accordance with the data subject's rights.
These include the:
- right to be informed
- right of access
- right to rectification
- right to be forgotten
- right to restrict processing
- right to data portability
- right to object
- rights in relation to automatic decision-making and profiling
- right to lodge a complaint with the supervisory authority.
Further information on how we process and protect your personal information in line with data protection legislation can be found in the section below.
More on data protection
You can exercise any of your data protection rights listed on this page under GDPR Article 15 to 22 by emailing our data protection team at data.protection@dover.gov.uk (opens in new tab)
Keep Me Posted
Sign up for email updates on council services.
Keep Me Posted (opens in new tab)