19 - Data COPY Flashcards
What is the main concern of using / transferring data across international borders?
The legislation around data handling may be more stringent in one of the two countries and organisations need to take extra care to not breach local standards.
List the eight conditions of the POPI Act in South Africa.
- Accountability
- Processing limitation
- Purpose specification
- Further processing
- Information quality
- Openness
- Security safeguards
- Data subject participation
Describe the POPI Act condition of “Accountability”.
The party responsible for processing the data is also responsible for compliance with POPI.
Describe the POPI Act condition of “Processing Limitation”.
Information must be processed in a fair, lawful and relevant manner, after consent is given by the data subject.
Describe the POPI Act condition of “Purpose Specification”.
Personal information must be collected for a specific purpose.
Record keeping to be destroyed when personal data is no longer relevant or authorised to be held.
Describe the POPI Act condition of further “Further Processing”
Further processing must be compatible with the initial collection prupose.
Describe the POPI Act condition of “Information Quality”
Data completeness, accuracy and updates to be ensured by holder of the data.
Describe the POPI Act condition of “Openness”
Documentation to be maintained on all processing operations and maintaining transparency on data use.
Describe the POPI Act condition of “Security safe-guards”
Integrity and confidentiality of personal data must be secured and all processing done only by authorised operators.
Notification to be done on security compromises.
Describe the POPI Act condition of “Data subject participation”.
The data subject may request confirmation of personal data held and request correction or deletion of any inaccurate, misleading or outdated information held.
Aside from criminal action and fines, what is another damaging effect of data breaches occurring within a company’s data bases?
- Damage to reputation
2. The ability to retain and attract clients.
Give the aspects that a data governance policy should aim to cover.
(5)
- The specific roles and responsibilities of individuals in the organisation with regards to data.
- How an organisation will capture, analyse and process data.
- Issues with respect to data security and privacy
- The controls that will be put in place to ensure that the required data standards are applied
- How the adequacy of the controls will be monitored on an ongoing basis with respect to data usability, accessibility, integrity and security.
Give the data governance risks (4).
Failure to have adequate data governance policy can lead to?
- Legal and regulatory non-compliance
- Inability to rely on data for decision making
- Reputational issues
- Incurring additional costs
Give a data concern around mergers and acquisitions. (3)
- Should data be combined into one system
- Which company’s system to use
- Data aggregation issues.
Give the main risks associated with data.
- The data are inaccurate or incomplete
- The data are not credible due to being insufficient volume, particularly for the estimation of extreme outcomes.
- The data are not sufficiently relevant to the intended purpose
- Past data may not reflect what will happen in the future.
- Chosen data groups may not be optimal
- The data are not available in an appropriate form for the intended purpose.
Why may past data not be an accurate reflection of future experience.
- Past abnormal events
- Significant random fluctuations
- Future trends not being reflected sufficiently in past data
- Changes in the way in which past data was recorded
- Changes in the balance of any homogeneous groups underlying the data
- Heterogeneity with the group to which the assumptions are to relate
- The past data may not be sufficiently up to date
- Other changes
State the “data protection principle” which may be difficult to meet when using big data
Personal data should be adequate, relevant and not excessive for the purposes concerned.
How can companies avoid big data being excessive and personal for the given purpose?
Anonymisation can be used to ensure that the data is not considered to be personal data.
List the main uses that actuaries make of data.
- Premium rating, product pricing and determining contributions
- Setting provisions
- Experience analysis
- Risk management - underwriting and reinsurance
- Investing
- Accounting
- Management information
- Marketing
- Administration
List the key data required for active members when valuing a pension scheme
- Membership ID / number
- Date of birth
- Date of joining employer
- Date of joining the scheme
- Date / age of retirement
- Current salary
- Salary scale / growth assumptions
- Category of membership
- Dependents - marital status
- Age of dependants
- Data from previous valuations for reconciliations
Outline the design features of a good proposal form.
- Collects data at an appropriate level - including data that are not currently used but may be used in the future
- Be clear and unambiguous - to capture the correct information
- Have inputs that are quantitative as far as possible
Give a design feature of the claims form in order to store good quality data.
Should be clear and unambiguous and link to the proposal form - to cross check information
Give features of data inputting processes that can ensure that good quality data is stored by a company.
- Inputs should be in the same order as the proposal form
- Staff that are inputting data should be trained
- Financial incentives for accurate inputting
- Data systems should have data validation checks - blank entries and sensible entry values
- Send policyholders copies of the key information in order to check all values are captured correctly
Give the data system features that can help ensure that good quality data is stored by an insurance company.
- The system should be capable of storing information so that historical data is available for future pricing exercises
- System should be robust yet flexible
- System should be secure - restricting access of people who can manipulate data
- Regular checks of data movements and changes
- Single integrated systems can make data handling easier