8E + Flashcards
On what basis can insurers treat the disabled less favorably
Only if justified on the basis of actuarial or statistical information
What happens if an insurer can’t prove why they’ve treated someone unfairly?
Compensate for financial loss/inconveniece
Which type of schemes does the Test Achats not apply to?
Group schemes
4 key elements of DPA 2018
- sensitive data kept confiedential
- Restricting access rights
- Parental consent age
- Enhanced ICO powers
ICO powers
- Most serious – up to £17.5m or 4%
- Criminal proceedings if records altered
What happens to controllers where a processor is involved?
They are not relieved of their obligations
Can an online identifier be personal data?
Yes, e.g., an IP address
6 data protection principles
- Lawfulness
- Purpose limitation
- Data minimisation
- Accuracy
- Storage limitation
- Confidentiality
How to make processing lawful?
Firms need to identify a lawful basis
Six lawful bases for processing data
- Consent
- Contract
- Legal obligation
- Vital interests
- Public task
- Legitimate interests
8 GDPR rights
1, Be informed
2. Access
3. Rectify
4. Erase
5. Restrict processing
6. Data portability
7. Objection
8. Automated decision making an dprofile
SAR abbreviation
Subject access request
How long do companies have to respond to SARs?
Within one month (can take 2)
How can an individual request rectifiaction?
Verbally on in writing
Is the right to erasure absolute?
No