CH 10 Flashcards
CONSUMER PROTECTION AND DISPUTE SOLUTION
What is the Data Protection Act of 1984
This Act gave individuals protection, if an organisation lost, disclosed without authorization or retained inaccurate information about them. Computer Data was defined as Data for the purpose of this Act
What is the Data Protection Act of 1998
This replaced the Data Protection Act of 1984, and was concerned with the regulation of data transfer, but not confined to computer data. Individual information stored in pother types of systems fell in this scope,as long as the system were organised in a way data could be interrogated by name
General Data Protection Regulation(GDPR)
Came into effect 25/05/2018,has Implication on every global firm that holds or use data on EU citizen and residents. Non-EU organisation doing business in the EU and holding EU personal data need to comply with this regulation
Data Protection Act 2018
recieved assent on 25/05/2018. It modernizes data protection laws to ensure they are effective in today’s digital economy
What provision does the Data Protection Act 2018 apply
It applies the provision of General Data Protection Regulation and the Law enforcement Directive to UK law
Who does the GDPR apply to
It applies to controllers and processors,the controller says how and why personal data is processed and the processor acts on the behalf of the controller
The GDPR places specific legal obligation on who
It places specific legal obligation on the processors, like having to maintain records of personal data and processing. This obligation are new requirement under the GDPR
Are controllers relieved of their obligations, where a processor is involved
No, they are not, the GDPR places further obligations on controllers to ensure their contracts with processors comply with GDPR
What information does the GDPR apply to
It applies to personal data, including changes reflecting in technology and the way in which information is collected.
It applies to both personal data and manual filing system s
Which categories are included, in sensitive personal data
- race
- ethnic origin
- politics
- religion
- trade union membership
- genetics
- biometrics
- health
- sex life
- sexual orientation
Under the GDPR, the data protection principles are similar to those of Data Protection Act 1998 with some detailed addition, which is the most significant addition
The most significant addition is the accountability principle, where by the GDPR requires firms to show how they comply with principles
What is required for processing to be lawful under the GDPR
Firms need to identify a lawful basis before the can process data and document it
How does the GDPR lawful basis have an effect on an individuals right
a firm relies on someone’s consent, the individual usually has stronger rights
What are the new GDPR rights
- The right to be informed
- The right of access to their information, free of charge
- The right to rectification
- The right to erasure
- The right to restrict processing
- The right to data portability
- The right to object
- right in relation to automated decisions
The right to be informed
Data subjects have a right to receive information about how and why their information is used ad what their rights are.
This is provided in the form of a privacy note
What are the certain, mandatory information to be included in a Privacy note
- detail of controller/processor
- what will be done with their data
- who the data will be passed to
- how long it will be kept for
- what their individual rights are
The right of access
Individuals have the right to their information, free of charge. It is referred to as a subject access request
The right to erasure
It is often referred to as right to be forgotten. It doesn’t always apply in insurance,because insurance customer information may be required for longer for than expected as some policy can be claimed against many years after event can take place.
The right to object
In insurance , all individuals have the right to object direct marketing and this right should be explicitly bought tot heir attention
Under the GDPR which officer is mandatory for some companies to have
A Data Protection officer is mandatory, but for majority small/medium companies insurance brokers will not be required
GDPR introduces duty on all organisation to report certain types of data breach to relevant authority and the individuals affected
GDPR provision breaches lead to up to 20 M pounds or 4% of global annual turnover of the preceding financial year
Other breaches lead to up to 10 M pounds or 2% of global annual turnover of the preceding financial year ,whichever is greater
The GDPR restricts the transfer of personal data to
It restricts the transfer of data outside the European Union, to third countries or international organisation
The main elements of the Data Protection act 2018
- General Data Processing
2. Regulation and enforcement
Subjects of ethics are tied up with
They are tied up with issued of morality
Ethical Standards are concerned with
They are concerned with the way in which moral outcome ca be achieved in a given circumstance
According to ethical standards what is the hallmark of a professional
Is the ability to step back from issues of self interest and provide competent independent advise in the interest of the client. This will inspire public trust in their services
Code of conduct
All professional bodies produce a code, to which each member must adhere.They are not forcible by law, but may lead to penalties if failure to comply
Do professional bodies take disciplinary action against members who fail to comply by their codes like trade bodies
No, they do not take any disciplinary action to their members, it follows failure to comply with the code will bring members into disrepute
What do the codes of ethics of the CII represent
This represents a set of ethical principles for insurance and financial services professionals world wide
What is the basis of the CII code of ethics
It’s principal based, thus takes it is flexible enough to take into account wide range of different roles undertaken within the sector
what are the overlapping requirements of ethical behavior for CII
Integrity Fairness Service Client's Interest Compliance
The code of the CII is more concerned with
It is more concerned with behavior and attitude