2 - Data Protection Concepts Flashcards
What is the leading document cited for the definition of personal data?
Article 29, Working Party Opinion 4/2007
What is defined in Article 29 Working Party Opinion 4/2007?
The definition of personal data.
What is the definition of personal data?
- Any information,
- relating to,
- an identified or identifiable
- Natural Person
What 3 factors should you examine to determine whether information is considered personal data?
- Nature = objective and subjective
- Content = wide interpretation
- Format = includes any information
What factors should you examine to determine whether personal data RELATES TO an individual?
Content, purpose and result
True or False: Personal data identifies a natural person when it can be combined with other pieces of information that will allow the individual to be distinguished from others?
True.
Key factor for meeting identifiable component of definition of personal data.
Personal data = any information, relating to an identified or identifiable natural person.
True or False: If a data controller has information that when viewed collectively may point to a natural person, but the costs and time required to make this connection are extensive – this qualifies as meeting the definition of identifiable under the GDPR?
FALSE.
Test for meeting the definition of identifiable does weigh objective factors, including the costs, time and technology required to make such connection.
Connection must be reasonably likely.
True or False: The GDPR recognizes that when the possibility of singling out an individual does not exist or is negligible, the person should not be considered as identifiable.
True. In such case the information is not considered personal data under the GDPR.
True or False: Do dynamic IP addresses constitute personal data?
True. On grounds that person could be “identically identified” if combined with data held by internet services providers.
Dynamic IP address - temporary address to devices connect to a network that continually changes over time
Does the GDPR apply to anonymous information?
No. Such information does not relate to an identified or identifiable natural person or to personal data rendered anonymous in such a manner that the data subject is not or no longer identifiable.
True or False: Complete anonymization is a manageable task for a single organization
False - it is difficult
What is the definition of pseudonymisation?
processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such information is kept separate and subject to technical and organisational measures to ensure that the personal data is not attributed to an identified or identifiable natural person.
True or False: Aggregated data of statistical purposes is considered personal data.
Likely False. But take care.
Are there limiting factors on definition of “natural person?
Generally no. Applies regardless of country of residence, subject to territorial scope of GDPR.
What are the special categories of sensitive personal data.
- Racial or ethnic origin
- Political opinion
- Religious or philosophical beliefs
- Trade union membership
- Genetic data
- health data
- Sexual orientation