Accountability and International Data Transfers Flashcards
What is accountability with respect to the GDPR?
Accountability – different obligations with which an organisation must comply with in order to show and evidence their compliance with the data protection framework.
What are the six principles that govern the data controller’s accountability under the GDPR?
Lawfulness, fairness, transparency,
Purpose limitation
Data minimisation
Accuracy
Storage Limitation
Integrity and Confidentiality
Whose responsibility is it to demonstrate compliance with accountability principles under the GDPR?
Data Controller.
Data controller must comply with the six principles and also must be able to DEMONSTRATE COMPLIANCE with the principles of data processing.
What are the six principles of data processing?
- Transparency (lawfulness and fairness)
- Purpose Limitation
- Data minimisation
- Accuracy
- Storage limitation
- Integrity and COnfidentiality.
What are 3 areas the data controller could consider utilizing to comply with implementing appropriate data protection policies?
Three areas the data controller could consider to comply with the requirement to implement appropriate data protection policies:
1. Internal policies
2. Internal allocation of responsibilities
3. Training
What is privacy by design?
Privacy by Design, consider in planning and execution states, but also create products with built in ability to manage and fulfil data protection controls.
What is privacy by default?
Privacy by Default, requirement that companies implement appropriate technical and organisation measures to ensure that by default, only personal data necessary for each specific purpose of the processing is processed.
What is a DPIA?
DPIA is process by which companies can systematically assess and identify the privacy and data protection impacts of any products.
Data Protection Impact Assessment;
When is a DPIA used?
Use by companies to identify and address any data protection issues that may arise when developing new products and services.
When is DPO required?
Data Protection Officer; DPO is required where:
(a) Processing is carried out by public authority
(b) If core activities of the controller/processor consists of regular and systematic monitoring of individuals on a large scale,
(c) Care activities of processing includes special categories of personal data on a large scale.
True or False. DPO is required when processing involves processing special categories of personal data on large scale.
True.
True or False. Public authority based processing does not require DPO.
False.
True or False. Processing that involves regular and systematic monitoring of individuals on a large scale does not require a DPO.
False.
True or False: Transfers of personal data to any country outside of EEA may only take place subject to the conditions of Chapter 5 of the GDPR.
True.
What are the methods to allow international data transfers under Article 5 of the GDPR?
- Adequacy Decision
- Appropriate Safeguards
- Derogations