11. Data protection. Flashcards
T/F: data protection legislation applies only to that collected or recorded in electronic form.
FALSE
The most recent primary legislation regarding data protection in the UK is the …
Data Protection Act (2018)
The Data Protection Act (2018) implements and supplements the EU’s ….
General Data Protection Regulation (GDPR)
GDPR: General Data Protection R*
regulation
“…” means any information relating to an identified or identifiable living individual.
personal data
“Personal data” means any information relating to an [I or I LI]*
identified or identifiable living individual
“processing” information can involve: C*, R, S, A, D, C, D
collection
“processing” information can involve: C, R*, S, A, D, C, D
recording
“processing” information can involve: C, R, S*, A, D, C, D
storage
“processing” information can involve: C, R, S, A*, D, C, D
adaptation
“processing” information can involve: C, R, S, A, D*, C, D
disclosure
“processing” information can involve: C, R, S, A, D, C*, D
combination
“processing” information can involve: C, R, S, A, D, C, D*
destruction
Data protection (does / does not) require safeguards where automated decision making occurs on the basis of information provided by/collected on data subjects.
does
DC* determine the purpose and means of processing personal data.
data controllers
DP* are responsible for processing personal data on behalf of a controller.
data processors
DS* are identified or identifiable individuals (not companies) to whom personal data relates.
data subjects
A limited company (can / can not) be a ‘data subject’.
can not
Data protection legislation applies to … organisations.
all
Opinions, as distinguished from facts, (do / do not) fall within the scope of data protection legislation.
do
The person responsible for data regulation in the UK is the …
Information Commissioner
Data protection law in the UK uses a (prescriptive / risk based) approach.
risk based
Information which an individual has published about themselves, for example a professional profile, (is / is not) nevertheless covered by data protection legislation.
is
Any data breach must be reported to the information commissioner within …
72 hours
Individuals whose data is subject to a breach need only be informed directly if the case is …
high risk
Data protection principles: LFAT* (G, C, OAH), PL (S, E, L), DM (A, R, NE), A (C), SL (RP), I (CAS)
lawfullness, fairness and transparency
Data protection principles: LFAT (G*, C, OAH), PL (S, E, L), DM (A, R, NE), A (C), SL (RP), I (CAS)
grounds for holding the data
Data protection principles: LFAT (G, C*, OAH), PL (S, E, L), DM (A, R, NE), A (C), SL (RP), I (CAS)
clarity in how the data is used
Data protection principles: LFAT (G, C, OAH*), PL (S, E, L), DM (A, R, NE), A (C), SL (RP), I (CAS)
openness and honesty in how the data is used from the start
Data protection principles: LFAT (G, C, OAH), PL* (S, E, L, CfNP), DM (A, R, NE), A (C), SL (RP), I (CAS)
purpose limitation