i found this info relating data protection within a business:
4. How am I allowed to use the personal information I hold?
The way you use may use the personal information you hold is governed first by the eight Data Protection Principles. These require that information is:
* fairly and lawfully processed;
* processed for limited purposes;
* adequate, relevant and not excessive;
* accurate;
* not kept longer than necessary;
* processed in accordance with individuals' rights;
* kept secure;
* not transferred to countries outside the European Economic Area without adequate protection.
As part of complying with the principles, you must:
* meet at least one of six conditions in order to process personal information;
* meet at least one of a number of further conditions in order to process sensitive personal information (e.g. information about a person's health, ethnic origin, political opinions, trade union membership etc.); and
* inform individuals when their information is collected.
The terms of your notification with the Information Commissioner will also affect the way in which you may use the personal information you hold. If you want to use the information for new purposes for which you have not notified, you must update your notification before you begin using the information in a new way."
it came from this link:
http://www.dca.gov.uk/ccpd/faqdp.htm#2d
hope it helps