Accountability and International Data Transfers Flashcards

1
Q

What is accountability with respect to the GDPR?

A

Accountability – different obligations with which an organisation must comply with in order to show and evidence their compliance with the data protection framework.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are the six principles that govern the data controller’s accountability under the GDPR?

A

Lawfulness, fairness, transparency,
Purpose limitation
Data minimisation
Accuracy
Storage Limitation
Integrity and Confidentiality

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Whose responsibility is it to demonstrate compliance with accountability principles under the GDPR?

A

Data Controller.

Data controller must comply with the six principles and also must be able to DEMONSTRATE COMPLIANCE with the principles of data processing.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are the six principles of data processing?

A
  1. Transparency (lawfulness and fairness)
  2. Purpose Limitation
  3. Data minimisation
  4. Accuracy
  5. Storage limitation
  6. Integrity and COnfidentiality.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are 3 areas the data controller could consider utilizing to comply with implementing appropriate data protection policies?

A

Three areas the data controller could consider to comply with the requirement to implement appropriate data protection policies:
1. Internal policies
2. Internal allocation of responsibilities
3. Training

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is privacy by design?

A

Privacy by Design, consider in planning and execution states, but also create products with built in ability to manage and fulfil data protection controls.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is privacy by default?

A

Privacy by Default, requirement that companies implement appropriate technical and organisation measures to ensure that by default, only personal data necessary for each specific purpose of the processing is processed.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is a DPIA?

A

DPIA is process by which companies can systematically assess and identify the privacy and data protection impacts of any products.

Data Protection Impact Assessment;

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

When is a DPIA used?

A

Use by companies to identify and address any data protection issues that may arise when developing new products and services.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

When is DPO required?

A

Data Protection Officer; DPO is required where:
(a) Processing is carried out by public authority
(b) If core activities of the controller/processor consists of regular and systematic monitoring of individuals on a large scale,
(c) Care activities of processing includes special categories of personal data on a large scale.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

True or False. DPO is required when processing involves processing special categories of personal data on large scale.

A

True.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

True or False. Public authority based processing does not require DPO.

A

False.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

True or False. Processing that involves regular and systematic monitoring of individuals on a large scale does not require a DPO.

A

False.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

True or False: Transfers of personal data to any country outside of EEA may only take place subject to the conditions of Chapter 5 of the GDPR.

A

True.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What are the methods to allow international data transfers under Article 5 of the GDPR?

A
  1. Adequacy Decision
  2. Appropriate Safeguards
  3. Derogations
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Define this concept: Adequacy Decision

A

Decision that third party country law provides an adequacy level of protection.

17
Q

Name current countries with adequacy decisions:

A
  1. Canada
  2. Uruguay
  3. Isle of Man
  4. Switzerland
  5. Israel
  6. South Korea
  7. Japan
  8. New Zealand
18
Q

Define this concept: Appropriate Safeguard

A

May be used to transfer internationally, these are legal tools design to ensure recipients of personal data are bound to GDPR like standard.

19
Q

What are some examples of appropriate safeguards?

A
  1. Binding Corporate Rules
  2. Standard Contractual Clauses
  3. Approved Codes of Conduct or Certification Mechanisms
20
Q

Define this concept: Derogations and Restrictions

A

Derogration and restrictions may be used as a method of last resort to transfer data internationally. They have specified restrictions.

21
Q

What are the factors required to transfer data internationally under a derogration?

A

One of the following

  1. Explicit Consent (with knowledge of risk of international transfer)
  2. Necessity for Contract Performance
  3. Public Interest
  4. Establishment of Legal Claim
  5. Protection of Vital Interest