Chapter 13 Flashcards
Act - electronic or manual
Both
T or F
-Aims to protect individuals from misuse of correct but confidential info and use of incorrect info
True
T or F
Data controller can be an individual or a company
True
T or F
Data is regulated by data act even if it just holds opinions about someone
True
Penalties of the act
4% global turnover or < 17m
Criminal convinction
NO potential liability for a court order directing the forfeiture, destruction or erasure of a database
T or F
The data controller is obliged to take all steps to ensure that data held about an individual is accurate
F reasonable steps not all steps
t or f
The data controller is obliged to keep the data subject informed of all personal data held or processed re that data subject
False - the data subject must request the information in accordance with their right of access
Is the data subject always entitled to compensation in the event the data controller is found to have inaccurate data?
No - a claimant may be able to claim compensation if they can show they have suffered damage as a result of contravention of the act. It is not a right of the act itself
Does the data subject have the right to request that accurate data held about them be destroyed?
Yes - The right to be forgotten; a right of the act
Are people entitled to have access to their records? Does it make a difference if company holding data is ltd or plc?
Yes - no difference
T or F
A principle of the data protection act is that the purpose for recording data must be made clear to the data subject
T - a company is in breach of this if they do not have information available as to what they use the data for
A data subject has the right to access data held about them unless the data are held in encoded form when access requires a court order
F - all data pertaining to a data subject are accessible by the data subject whatever the form in which they are held
Does a data subject whose rights to be infringed (inaccurate data held about them) can take action to rectify the inaccurate data
Yes
Exemptions to data protection act
Employer processing data in compliance with employment law
Processing of data for academic purposes
Information Commissioner - must be informed within 72 hours of any data breach - T or F
False - of a data breach which affects the rights and freedoms of individuals (if high risk = inform individuals as well)