Chapter 1 - GDPR Flashcards

1
Q

In what ways is GDPR extra territorial?

A
  1. Applies to data processors and controllers in the EU processing EU data subject personal data.
  2. Applies to data processors and controllers outside the EU who are processing EU data subject personal data for the purpose of selling goods or services or monitoring the behaviour of EU data subjects.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is something special data processors and controllers outside the EU have to do?

A

Appoint an EU representative

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What does Article 28 of the GDPR relate to?

A

Record keeping requirements

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is the maximum penalty under GDPR and what sort of offences can it be used for?

A
  1. 4% of global annual turnover or 20 million euros which ever is greater - not obtaining consent or not having privacy by design.
  2. 2% of global annual turnover for
    - not informing the regulator of a breach in a timely manner
    - not conducting a DPIA
    - breach Article 28 - record keeping requirements
  3. 2% of global annual turnover
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

How long do firms have to inform the regulator after discovering a data breach?

A

72 hours

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Are clouds exempt for GDPR?

A

No because it impacts data controllers as well.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What does Article 17 relate to under GDPR?

A

Right to be forgotten/erasure

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What does Article 23 relate to under GDPR?

A

Data minimisation - privacy by design - not giving access to those who don’t need it.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What are a data subject’s rights under GDPR?

A
  1. Right to consent
  2. Right to be forgotten - Article 17
  3. Right to access data
  4. Right for data portability
  5. Right to privacy by design - Article 23 - data minimisation
  6. Right to be informed of a breach
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

When is a Data Protection Officer required?

A

When there are systematic and large scale processing of personal data or processing of special category data.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What are the qualities and requirements for a DPO?

A
  • Sufficiently trained and knowledgeable
  • Report to the highest levels of management
  • Adequately resourced
  • Contact details shared with DPA
  • Avoids conflicts of interest
How well did you know this?
1
Not at all
2
3
4
5
Perfectly