Non-Spatial Data Standards - Data Standards - UK HER Manual
Non-Spatial Data Standards
Non-Spatial Data Standards
In addition to the geospatial data standards set out above, there are also data standards for non-spatial data which are applicable to HERs.
Dublin Core Metadata Standard
UK government guidance recommends that the Dublin Core metadata schema is used when sharing tabular data, such as CSV files and spreadsheets. The Dublin Core schema originated in 1995 and consists of a set of fifteen core elements (properties) for describing resources (set out below). The Dublin Core schema has since been formally standardised as ISO 15836.
The 15 core elements of the Dublin standard are as follows:
|
Element |
Description |
|
Title |
The name given to a resource by its creator. |
|
Subject |
The topic of the resource, given in keywords or phrases which describe the subject or content of the resource. |
|
Description |
A text description of the contents of the resource, including abstracts in the case of document-like objects or content descriptions in the case of visual resources. |
|
Type |
The general type of the resource, such as text, image, database, etc. |
|
Source |
The work from which the resource is derived, for example the source of an HTML page might be a paper volume. |
|
Relation |
The relationship to other resources, for example images in a document. |
|
Coverage |
The spatial and temporal coverage of the information contained in the resource. |
|
Creator |
Person(s) or organisation(s) involved in creating the original resource. As an aid to resource discovery it may be helpful to record both named individuals and their organisations. |
|
Publisher |
The publisher, distributor, department or other entity(ies) responsible for making the resource available. |
|
Contributor |
An entity (person, organisation or service) responsible for making contributions to the content of the resource. |
|
Rights |
Statement of copyright or other rights relating to the resource. |
|
Date |
Dates when the resource was created, published, released, maintained or updated. A number of dates may need to be recorded. This is not to be confused with the date of the content of the resource. |
|
Format |
The format in which the data is represented, for example text, HTML, ASCII, executable application, JPEG image, etc. The size of the resource and the medium on which it is held may also be recorded. |
|
Identifier |
A unique identifier for the resource, for example URLs, ISBN number or internal identification number. |
|
Language |
The language(s) of the intellectual content of the resource. |
Guidelines exist for each of the Dublin Core elements to assist in creating metadata content, whether this is done from new or by converting an existing record into another format.
Other Relevant Data Standards
As well as complying with heritage data standards, HERs are also required to comply with other UK data standards.
GDPR and Data Protection Act
The General Data Protection Regulation (GDPR) and Data Protection Act (2018) control how personal and sensitive information is used by organisations, businesses and the government. The Data Protection Act (2018) is the UK’s implementation of the General Data Protection Regulation (GDPR). Although the UK has since left the EU, the GDPR is retained in domestic law as the UK GDPR. These pieces of legislation regulate strictly how such information may be used and this legislation is applicable to everyone involved in processing or managing that data.
The rules which govern how personal and sensitive information can be used are known as the Data Protection Principles. The six data protection principles are as follows:
- The processing of personal data must be lawful, fair and transparent.
- The purpose for which personal data is collected on any occasion must be specified, explicit and legitimate, and personal data so collected must not be processed in a manner that is incompatible with the purpose for which it is collected.
- Personal data must be adequate, relevant and not excessive in relation to the purpose for which it is processed.
- Personal data undergoing processing must be accurate and, where necessary, kept up to date.
- Personal data must be kept for no longer than is necessary for the purpose for which it is processed.
- Personal data must be processed in a manner that includes taking appropriate security measures as regards risks that arise from processing personal data. The risks referred to include (but are not limited to) accidental or unauthorised access to, or destruction, loss, use, modification or disclosure of, personal data.
It is likely that most host organisations will require HER staff and volunteers to attend compulsory GDPR and Data Protection training, and some host organisations may also have specialist staff who can advise HER professionals about how the GDPR applies to the HER. If GDPR training is not offered by the host organisation, it is suggested that HER professionals should arrange to attend suitable training offered by a third party. Further information and resources about the UK GDPR are provided by the Information Commissioner’s Office.
There are two specific areas where GDPR and the Data Protection Act are especially applicable to HERs: the personal details of HER users and personal details held as part of the HER itself.
Regarding how the HER handles information about HER users, all relevant documentation, such as user-access forms and correspondence (by letter and by email), should include clear statements informing users about how their information may be collected, used, processed, shared, stored or retained (privacy notices) and seek their consent where necessary.
More widely, it is important to ensure that all HER content, both hard copy and digital, has been checked for compliance with the UK GDPR and Data Protection Act. This includes the content of the HER’s Reference Collection. It is essential that where personal information is included in material within the Reference Collection suitable measures, such as redaction, are employed to ensure compliance with GDPR and the Data Protection Act.