11 - Data Law Flashcards

1
Q

What’s an example of data?

A
  • Customer data
  • Employee data
  • Supplier data
  • Production data
  • Intellectual data
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What does the data protection act 2018 govern?

A

The use of personal information and impacts on how information systems are used by business.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

How many principles of GDPR are there?

A

7

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What’s the 1st principle of GDPR?

A

Lawfulness, fairness and transparency:

Basis must be lawful for processing personal data be open with the use.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What’s the 2nd principle of GDPR?

A

Purpose limitations:

Must be clear with purpose of data, record purposes + specify + only can use for new purpose and notify.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What’s the 3rd principle?

A

Data minimisation:

Don’t hold more than you need + periodically review data held and delete the unnecessary.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What’s the 4th principle?

A

Accuracy:

Must be accurate, updated and corrected. Delete if not correct.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What’s the 5th principle?

A

Storage limitation:

Justify how long you keep it, set retention period + periodic review and deletion.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What’s the 6th principle?

A

Security:

Physical and online processes must be in place.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What’s the 7th principle?

A

Accountability:

Records and processes to demonstrate compliance.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

How many individual rights are there?

A

8

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Name 2 of the individual rights

A
  • Be informed
  • Of access
  • To rectification
  • To erasure
  • Restrict processing
  • Data portability
  • To object
  • Rights to automated
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Who is the regulator for the UK?

A

ICO.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What must a company report to ICO?

A

A breach that poses a risk to people.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is the time limit to support?

A

72 hours.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What’re the sanctions for a data breach?

A
  • Monetary penalties
  • Enforcement notices
  • Prosecutions
  • Undertakings
17
Q

What’s the highest fines for data breaches?

A

£17.5M

Or

4% of total annual turnover in preceding year.

18
Q

Name an example of enforcement

A

Marriott Hotels
- Fined £18.4M for major data breach where guest names, contact info and passport details were compromised.