Data protection (GDPR) GDPR summary The GDPR, and also the Data Protection Act 2018 (DPA 2018) took effect on 25th May 2018. The main rules are in the GDPR. These ...
Brexit updates From 1st January 2021, EU law is incorporated into UK law but with the UK free to amend it, subject to any agreement to the contrary. Previo...
Guidance on subject access requests The Information Commissioner’s Office has issued revised guidance on subject access requests (SARs) under the GDPR. As outlined in the...
Morrisons held not liable for malicious disclosure of data by employee The Supreme Court has reversed lower court decisions which had found Morrisons liable. The decision is important generally on how far employ...
Seeking information from a GP or other doctor Summary From a data protection point of view, OH should only ask the GP or specialist for information that is necessary. Workers should not ...
Brexit Updates on this include new GDPR guidance from the Information Commissioner. It is still unknown what deal (if any) will be struck between t...
Guidance on data controllers and processors The Information Commissioner’s Office has published new guidance on this in relation to GDPR. The guidance is at https://ico.org.uk/fo...
Litigation motive in subject access requests The Court of Appeal upheld a decision by the GMC to disclose an expert report to a patient despite the patient’s data being mixed with...
Pressure to breach OH legal/ethical obligations The issue In practical terms, the problems often facing OH practitioners tend to arise from requirements imposed by the employer that confli...
Freedom of information requests Generally The Freedom of Information Act 2000 applies to public authorities only, unlike the GDPR which applies to both public and private b...