Basics Flashcards
Define GDPR
General Data Protection Regulation
Define personal data and provide examples
Personal data is any information that can directly or indirectly identify a living individual. These include:
Name
Date of birth
Address
Email address
Mobile number
Physical characteristics (inc gender)
Location data
IP Address
Define special category data and provide examples
Special category data is sensitive personal data and are listed under Article 9 of the GDPR. These include:
Race or ethnic origin
Political opinions
Religious beliefs
Trade union membership
Genetic data
Biometric data
Health data
Sex life or sexual orientation
Define data subject
An individual whose personal data is being processed or controlled.
What is a data controller?
An entity that determines the purposes and means of processing personal data.
What is a data processor?
An entity that processes personal data on behalf of a data controller.
Define a data breach
This is a security incident in which personal data is accidentally or unlawfully destroyed, lost, altered, disclosed, or accessed.
List the seven key principles set out in GDPR
Lawfulness, fairness and transparency
Purpose limitation
Data minimisation
Accuracy
Storage limitation
Integrity and confidentiality
Accountability
What are the six lawful bases for processing personal data?
Consent
Contract
Legal Obligation
Vital Interests
Public Task
Legitimate Interests