18. GDPR Flashcards

1
Q

GDPR

GDPR

A
  1. Regulation in EU Law on data protection and privacy
  2. All individuals within the EU and EEA

EU - European Uniion
EEA - European Economic Area

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

GDPR

Customers in EU/EEA

must comply

A

If you have customers in EU/EEA, company MUST adhere to GDPR

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

GDPR

Violations and Fines

A
  1. Up to EUR; 20m
  2. 4% annual worldwide turnover (preceeding financial year)

Whichever is greater

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

GDPR

Personal Consent

A

Personal data MAY NOT be processed
UNLESS;
1. Subject provided informed consent
2. At least one legal basis to do so

  • Unless express consent given, its not legal to process it
  • Anything that can be identified as yours
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

GDPR

Restrictions

A
  1. Lawful interception
  2. National Sceurity
  3. Military Police
  4. Justice System

  • Above have rights to the information and restricts GDPR
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

GDPR

Personal Data

A
  1. Names
  2. Email addresses
  3. Addresses
  4. Unsubscribe confirmation URLS (contain email/name/IP address)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

GDPR

End User Rights

A
  1. Right to access
  2. Right to erasure
  3. Data portability
  4. Breach notification

  1. Right to access - Data controllers must provide free copy on request to subject
  2. Right to erasure - subjects have “right to be forgotten”
  3. Data portability - Users have right to access their data in electronic format
  4. Breach notification - Subjects must be notified of breaches within 72 hours
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

GDPR

Right to access

End User Rights

A

Data controllers must provide free copy on request to subject

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

GDPR

Right to erasure

End User Rights

A

subjects have “right to be forgotten”

  • Where there are no laws or regulations for a company to be keeping your data
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

GDPR

Data Portability

End User Rights

A

Users have right to access their data in electronic format

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

GDPR

Breach Notification

End User Rights

A

Subjects must be notified of breaches within 72 hours

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

GDPR

Privacy by Design

A

Care MUST be taken to ensure personal data is secure

  • Only data that is “absolutely necessary for completio of duties” is stored
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

GDPR

Data Protection Officers

A

Companies MUST appoint a Data Protection Officer

  • Where companies whose activities involve data processing and monitoring
  • Senior management liable. Does not mean other people are not
  • Remember due dilligence and due care
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

GDPR

Legacy Laws in EU and between EU and US

A
  1. EU Data Protection Directive
  2. EU-US Safe Harbor
  3. Privacy Shield
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

GDPR

EU Data Protection Directive

Legacy Laws in EU and between EU and US

A

Predecessor to GDPR

  • Pro privacy law
  • Organisations must notify individuals how they gather and use data
  • Allow subjects to opt out of sharing your data with third parties
  • Subjects must opt in for use of most sensitive data
  • Not legal to transport data outside of EU unless that country has adequate (same level) of privacy protection
  • US as example does not have same level of protections
  • No longer exists
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

GDPR

EU-US Safe Harbor

Legacy Laws in EU and between EU and US

A

Framework on data exchange

  • Allowed US companies access to EU entities under EU privacy laws
  • No longer exists
  • Invalid in EU court of justice Oct 2015
17
Q

GDPR

Privacy Shield

Legacy Laws in EU and between EU and US

A

Framework on data exchange

  • Allowed US companies access to EU entities under EU privacy laws
  • No longer exists
  • Invalid in EU court of justice July 16th 2020