Meeting the Data Protection Act 2018 requirements

We all have responsibilities under the Data Protection Act 2018. There are 7 key principles and these are:

  1. Lawfulness, fairness and transparency 
  2. Purpose limitation
  3. Data minimisation
  4. Accuracy
  5. Storage limitation
  6. Integrity and confidentiality 
  7. Accountability

Here, we are going to discuss integrity and confidentiality. 

It states that you must have appropriate security measures in place to protect the personal data you hold. It is best practice not to take personal data out of the work setting. If you are doing this you must ensure that you have the correct permissions in place and that the data you are storing is secure. 

You can do these using any of the following methods:

  • Password protect documents - this can be set up for individual documents. Go to file>info>protect document>encrypt with password
  • Ensure that your devices (laptops, ipads, tablets, computers and phones) are password protected or you need biometric information (face/finger print) to access them
  • When purchasing an external memory device (memory stick) choose one that has a password protection system
  • If you are using an external memory device without a password system you can encrypt the device by going to BitLocker, which is a Microsoft programme, and follow the instructions to set up encryption

For further information you can visit the Information Commissioners Office Website here or ask us for further information. 


Last modified: Friday, 13 February 2026, 11:49 AM