Hacker News new | ask | show | jobs
by pjc50 4415 days ago
"Handing to one other organisation in confidence" != "public"

The answer is potentially yes, if you're handling people's information then they have a right to (a) correct it and (b) delete it. You can't just maintain dossiers on people forever without their consent. However, it may be exempt if it's administratively necessary to keep.

http://ico.org.uk/for_organisations/data_protection/the_guid...

(Really you have to look in the caselaw which is harder to find)