Chapter 10 Consumer protection and dispute resolution Flashcards
What is a data controller?
The party who keeps personal data on their customers and determines how and why it is processed
What is a data processor?
An organisation who processes data on a data controller’s behalf
Under GDPR who can be liable to customers if their personal data is breached?
Both the data controller and the data processor.
Identify eight principles of the EU General Data Protection Regulation.
Data must be:
Fairly and lawfully processed
Processed for limited purposes
Adequate, relevant and not excessive
Accurate
Not kept longer than necessary
Processed in accordance with individual’s rights
Secure
Not transferred to countries without adequate protection
~~~
Identify eight special categories of sensitive personal data under the GDPR where more stringent protection conditions apply.
Ethnic or racial origin.
Political opinions.
Religious beliefs or other beliefs of a similar nature.
Trade union membership.
Physical and mental health.
Sexual life.
Commission or alleged commission of an offence.
Any proceedings for any offence committed or alleged to be committed,
Identify seven requirements regarding a data subject giving consent for their data to be processed under the GDPR.
Consent must be:
Freely given
Specific
Informed
Unambiguous
Positive opt in
Easy to withdraw
Separate from other terms and conditions
~~~
Identify eight rights of a data subject under the GDPR
The right to be informed.
The right of access.
The right to rectification.
The right to erasure.
The right to restrict processing.
The right to data portability.
The right to object.
Rights in relation to automated decision making and profiling
~~~
Under the data protection laws, who is the data subject?
The person whose data is held.
What is the age below which parental consent is required under the Data Protection Act 2018
13
What Act implements the GDPR into English law?
Data Protection Act 2018
What is the maximum fine under the Data Protection Act 2018?
Euro20million or 4% of turnover
What are the five overlapping requirements of ethical behaviour?
Integrity
Fairness
Service
Client’s interest
Compliance
~~~
What is the purpose of the CII’s code of ethics?
Protect the reputation of the CII
Identify the 5 principles of the CII code of ethics
Comply with the code and law
Act with the highest ethical standards and integrity
Act in the best interests of the client
Provide a high standard of service
Treat people fairly
Identify the three key areas of training and competence
Assessing competence
Maintaining competence
Record keeping