C18 Data(1) : Data security and risks Flashcards

1
Q

Define personal data

A

Personal data relates to
1. Information iro an individual where the individual can be identified,
2. Data combined with other information could allow the individual to be identified.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Explain why the use of data is an increasingly significant issue for organisations

A
  • Organizations collect large amount of information on individuals as part of their operation.
  • Technology has made is possible to collect, store and use large amount of information on an individuals in diverse ways
  • Organizations have ethical responsibility to deal responsibly with personal data.
  • Balance between the privacy of individuals with the need of the organizations to make fair and responsible use of personal data in their operations
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Explain the purpose of data protection legislation

A

Aim/purpose of data protection legislation
1. Safeguard the rights of the individual with regard to how organisations can store and process personal data.
2. Regulations vary by jurisdication/countries

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

List 8 principles of UK’s data protection act that relate to processing personal data

A

Personal data must: PAF-TIANS
1. be obtained and processed for specified purpose
2. be adequate, relevant, and not excessive for the purposes concerned
3. be processed fairly and lawfully
4. not be transferred to a country or territory outside the EEA unless that country or territory ensures an adequate level of protection
5. be processed in accordance with the individual’s rights under the Act
6. be accurate and, where necessary, kept up to date
7. not be kept longer than necessary for the purposes concerned
8. be processed securely

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Give 3 examples of possible consequences of non-compliance with the data protection legislation when processing personal data.

A

Consequences of non-compliance with the data protection legislation when processing personal data can be significant
1. Individuals who commit criminal offenses may be prosecuted
2. Organisations might be fined for serious breaches
3. Lead to adverse publicity, which can lead to significant reputational damage to the organisation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Explain the relevance of anonymity to the definition of personal data

A
  • Ability to identify the individual to whom the information relates is crucial to the definition of personal data.
  • Obligations of an organisation are considerable less for anonymous data
  • Anonymous data may not constitute personal data
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

List 7 examples of information that can constitute sensitive personal data

A

Sensitive personal data can include information related to :
ERPP SMC
1. Ethnic or racial origin
2. Religious or similar belief
3. Political opinions
4. Physical or mental health condition
5. Sexual life
6. Membership of trade unions
7. Convictions, proceedings and criminal acts.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Conditions for processing sensitive personal data

A
  1. The data subject has given explicit consent
  2. It is required by law for employment purposes
  3. Needed in connection with the administration of justice or legal proceedings
  4. Needed to protect the vital interest of the individual or another person e.g. disclose medical condition in case of an accident at work
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Explain what is meant by ‘big data’, including its key characteristics

A

‘Big data’ : The increasing use of technology has now made it possible for the public and private sector to collect and analyse very large data sets of information

Big data can be characterised by:
1. very large data sets
2. Data brought together from different sources
3. Data which can be analysed very quickly, such as in real time

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Describe the main data protection considerations for organisations using bug data (TBD)

A

Conflict with personal data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Define data governance

A

Data governance is a term used to describe overall management of the : (A SIU)
Availability,
Security of the data employed in an organisation.
Integrity, and
usability

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Describe the purpose and typical content of the data governance policy

A

A data governance policy is a documented set of guidelines for ensuring the proper management of an organization’s data.
1. Specific rules and responsibilities of the individuals
2. how to capture, analyse and process data
3. Data security and privacy
4. Controls on data standards
5. Monitoring of adequacy of controls
6. Mechanism to meet legal and regulatory requirements

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

State risks to organisations if the do not have adequate data governance procedures

A

Organisations that do not have adequate data governance procedures can be exposed to risks related to:

  1. Legal and regulatory non-compliance
  2. Inability to rely on data for decision making
  3. Reputational issues
  4. Incurring additional costs (fine and legal costs)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Describe the key data issues when businesses are combined by merger or takeover

A

Where businesses are combined by merger or takeover, one of the key issues is whether the data for the two businesses should combined onto one system and , if so, which

+ Saving in overhead costs
- High conversion costs
- Risk in aggregating data sourced from different systems

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

4 risks that arise when using data, that relate to volume and quality of data

A
  1. Errors and omissions => Erroneous results or conclusions
  2. Insufficient data to produce credible results
  3. Insufficient data to produce credible results in adverse circumstances
  4. Other sources of data : Not a good proxy.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

List 8 reasons why historical data may not be a good reflection of future experience

A

Further data risks in using historical data.
Historical data may not be a good reflection of future experience due to: CC HOPART

  1. Changes in the way in which the past data was recorded
  2. Changes in the balance of any homogeneous groups underlying the data
  3. Heterogeneity with the group to which the assumptions are to relate
  4. Other changes e.g. medical advancements, social changes, economic changes
  5. Past data may not be up to date
  6. Past abnormal events
  7. Significant random fluctuations
  8. Future trends not being reflected sufficiently in the past data
17
Q

Risks in attempting to group data into broadly homogeneous groups

A

Risks in attempting to group data into broadly homogeneous groups
1. The resultant individual groups may be too small for a credible analysis
2. Merging data groups may lead to a data groups that is not sufficiently homogeneous

18
Q

3 other risks that are associated with the use of data

A

Further data risks (DLF)
1. Data may have been collected for a purpose=> not appropriate for a different purpose
2. Lack of confidence in the available data=> low confidence in conclusions
3. Format of data is not appropriate for the purpose required