Ch. 6 GDPR Principles Flashcards

1
Q

Lawfulness

A

personal data must only be processed when data controllers have a legal ground for processing the data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Fairness

A

DS must be aware their data will be processed, how this is done, with what purposes, allowing them to make informed decisions. Also requires an assessment on how the processing will affect the data subject.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Transparency + exceptions

A

Processing must be open and clear towards DS, in a timely manner.
Exceptions:
- When providing the information will involve a disproportionate effort or can be considered impossible
- To protect the data subject’s legitimate interest, in which case, the disclosure is expressly governed by the applicable law
- To preserve the confidentiality of the information, also regulated by the laws to which the data controller is subject

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Purpose limitation

A

Data controllers must only collect and process personal data to accomplish specified, explicit and legitimate purposes and not process personal data beyond such purposes unless the further processing is considered compatible with the purposes for which the personal data was originally collected

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Compatibility test:

A

Factors to take into account, and if the are met no additional legal basis is required for further processing:

  • Any link between those purposes and the purposes of the intended further processing
  • The context in which the personal data has been collected, in particular the reasonable expectations of data subjects based on their relationship with the controller as to their further use
  • The nature of the personal data
  • The consequences of the intended further processing for data subjects
  • The existence of appropriate safeguards in both the original and intended further processing operations’
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Data minimization

A

data controllers must only collect and process personal data that is relevant, necessary and adequate to accomplish the purposes for which it is processed

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Data accuracy

A

Controllers must take reasonable measures to ensure the data is accurate and, where necessary, kept up to date.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly