Information and Data Protection Office

  • Home
  • About
  • Information
    • For individuals
    • For organisations
    • For public authorities
  • Contact us
Make a complaint or report
Information and Data Protection Office > Information > Core duties of organisations and authorities

Core duties of organisations and authorities

This page explains the main legal responsibilities of organisations and public authorities that use personal data.


Controllers and processors

  • A data controller is the person or organisation that decides why and how personal data is used.
  • A data processor is the person or organisation that uses personal data on behalf of a controller.

Both controllers and processors are responsible for complying with the Freedom of Information and Data Protection Act 2026.

Lawful use of personal data

Personal data must only be used when there is a lawful reason to do so under the Freedom of Information and Data Protection Act 2026.

Personal data may be used when:

  • The individual has given consent
  • Use of the data is required by law
  • Use of the data is necessary to carry out a statutory or public function
  • Use of the data is necessary to protect vital interests
  • Use of the data is necessary for legitimate interests and does not override fundamental rights

Public authorities must mainly rely on statutory or public interest reasons.

Data protection principles

When using personal data you must ensure that it is:

  • Used lawfully fairly and transparently
  • Collected for specific and legitimate purposes
  • Limited to what is necessary
  • Accurate and kept up to date
  • Kept only as long as needed
  • Protected against unauthorised access or loss

Accountability and records

You must be able to show that you comply with the Freedom of Information and Data Protection Act 2026.

You should keep appropriate records of how personal data is used and protected.

Information

Information for individuals

Information for organisations

Information for public authorities

Resources

About the IDPO

News and publications

Site terms and privacy policy

The Information and Data Protection Office of the Hokorian State

The Information Data Protection Office is an independent regulator for information and data in the Hokorian State, as established under the Freedom of Information and Data Protection Act, 2026.

All public organisations in the Hokorian State use a ‘hokoriagov.net’ or ‘hokoria.net’ domain.