This lesson covers the foundational data protection concepts that apply to harassment data. It emphasizes purpose limitation, data minimization, transparency, and the roles of data controllers and processors to ensure compliant recordkeeping.
Data Protection Foundations for Harassment Data
This lesson covers the foundational data protection concepts that apply to harassment data. It emphasizes purpose limitation, data minimization, transparency, and the roles of data controllers and processors to ensure compliant recordkeeping.

Overview

Under GDPR and UK GDPR, organizations must protect personal data collected in harassment incidents. This includes incident reports, witness statements, and related communications used for investigation and remediation.

Purpose limitation and data minimization are essential. Collect only information that is necessary to understand and resolve the case. Clearly state the lawful basis for processing and document the purpose for which data is used.

Transparency and accuracy matter. Provide a privacy notice to data subjects, keep records current, and restrict processing to defined purposes and timeframes.

  • Identify categories of personal data
  • Assign data controller and processor roles
  • Document processing activities and retention needs