Understands and follows legislation and organisational policies that ensure information and data is handled securely and ethically

Add to favourites

On this page you'll find links to resources to help you to understand and follow legislation and organisational policies that ensure information and data is handled securely and ethically.  

Select your current capability level to jump to aligned resources:

When you open the links included on this page, you may be presented with messages about cookies. To find out more about what cookies are and how you can manage them safely, have a look at this guidance: Digital Unite - What is a Cookie?

Not at Level 1
Handling Information & Data icon which is a red hexagon with a computer and cogs inside

Understands and follows legislation and organisational policies that ensure information and data is handled securely and ethically

Not at Level 1 - I need to know more about the limitations on how information and data can be used or shared, and the laws that have to be followed, e.g. General Data Protection Regulation (GDPR). I need to find out how I can access my organisation’s data protection policies.

 

Data protection laws help make sure that information about people is used fairly, responsibly and securely. If you're new to data protection, this short introduction explains what data protection is, why it matters and why organisations have responsibilities when using personal information: Information Commissioner's Office - The benefits of data protection laws

To learn more about UK General Data Protection Regulation (GDPR) legislation, have a look at this webpage which provides an overview of the key principles included within it: Information Commissioner's Office - A Guide to the Data Protection Principles

If you're not sure about your organisation's rules and policies, you should speak to your line manager about how to access these and familiarise yourself with the contents. You may also want to look for relevant information on your organisation's intranet or by speaking to information governance colleagues, if these are available. 

For further resources, visit the Handling, Information and Data page of the Digital and Data Resource Hub

Level 1
Handling Information & Data icon which is a red hexagon with a computer and cogs inside

Understands and follows legislation and organisational policies that ensure information and data is handled securely and ethically

Level 1 - I know there are limitations on how information and data can be used or shared, and that there are laws that have to be followed e.g. UK General Data Protection Regulation (UK GDPR). I comply with my organisation’s training requirements on this and always follow local data protection policies. 

 

This handy guide to data protection covers some of the key points you need to know and think about when handling information and data safely: Information Commissioner's Office - Your Beginner’s Guide to Data Protection

Watch the two videos on this webpage for an introduction to some of the laws that need to be followed when using or sharing data, as well as an explanation of the key data protection terminology: Information Commissioner's Office - What is Personal Data?

For further resources, visit the Handling, Information and Data page of the Digital and Data Resource Hub. 

Level 2
Handling Information & Data icon which is a red hexagon with a computer and cogs inside

Understands and follows legislation and organisational policies that ensure information and data is handled securely and ethically

Level 2 - I understand the importance of using information and data securely and ethically and am aware of the risks of not doing so (e.g. loss of trust amongst people who use services). I have a good understanding of the laws, policies and guidelines in place to protect information and data, and I’m confident I adhere to these to protect myself and my organisation. 

 

Develop your understanding of why information and data must be handled responsibly by learning about individuals' rights over their personal information and how organisations should respond when those rights are exercised: Information Commissioner's Office - Individual Rights

Build on this by considering what can happen when organisations do not meet their data protection responsibilities, including how the Information Commissioner's Office (ICO) responds to concerns and takes regulatory action: ICO - How we handle concerns

Apply this understanding by exploring practical steps organisations can take to reduce the risk of personal data breaches and protect people's information appropriately: ICO - How to minimise the risk of personal data breaches happening

For further resources, visit the Handling, Information and Data page of the Digital and Data Resource Hub.

Level 3
Handling Information & Data icon which is a red hexagon with a computer and cogs inside

Understands and follows legislation and organisational policies that ensure information and data is handled securely and ethically

Level 3 - I confidently handle information and data in a legal, secure, and ethical way, and make sure my colleagues do the same. I fully understand the risks associated with data protection and always act on or escalate breaches if they occur. I keep informed about changes in relevant legislation, for example the introduction of the new Data (Use and Access) Act 2025, and how these will apply to my organisation. 

 

Keep your knowledge of data protection legislation up to date. Learn how the Data (Use and Access) Act 2025 has changed aspects of UK data protection law and consider what these changes could mean for how your organisation handles and uses personal information: Information Commissioner's Office - The Data (Use and Access) Act 2025: What does it mean for organisations?

As set out across data protection legislation, organisations have a responsibility to report and act on data breaches. To find out more about this, have a look at this guide: Information Commissioner's Office - Personal Data Breaches: A Guide

These videos look at some of the specific circumstances that are exempt from the application of data protection laws. They include helpful examples to understand how and when exemptions apply in practice: Information Commissioner's Office - Exemptions

To further explore different aspects of information and data security, have a look at the guidance and resources on these websites: 

For further resources, visit the Handling, Information and Data page of the Digital and Data Resource Hub.