Chapter 13 - Data protection laws Flashcards

1
Q

What is the purpose of the Data Protection Act 2018?

A

The Act is intended to protect individuals from misuse of the information about them. It sets out the data protection principles which apply to anyone who processes personal data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are data controllers?

A

Data controllers determine the purpose and means of processing personal data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are data processors?

A

Data processors are responsible for processing personal data on behalf of a controlle

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are personal subjects?

A

Personal subjects are identified or identifiable individuals (not companies) to whom personal data relates

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What data is covered under the Data Protection Act?

A

The Act applies where personal data is held on computer or manual files by any organisation (large or small, profit making or not, incorporated or not).
Personal data covers any information related to an identifiable living individual and it includes not only recording of facts but also expression of opinion about an individual

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is the Information Commissioner? What powers does it posess?

A

The Information Comissioner is the UK regulator for data protection.
It has statutory powers to enforce compliance with the Act.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

In what time frame must the Information Comissioner be informed about a data breach?

A

It must be informed within 72 hours of a data breach that affects the rights and freedoms of individuals (in high risk cases the individuals must be informed as well)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What are the punishments for non-compliance with the Data Protection act?

A

May result it:
* A criminal conviction if a crime has been committed under the Act
* A fine of up to approximately £18 million (is determined in Euros so depends on exchange rate) or 4% of the organisation’s global turnover

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What are the principles of data protection defined under the act? Define each (6)

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What are the rights of data subjects defined under the act? Define each (6)

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What are the exemptions to the act? Explain each (4)

A

The following are exempt from the provisions of the Act:
* Employers may process data in accordance with employment law, eg payroll
* Academic institutions (e.g. universities) if the data processed is for academic purposes
* Scientific and historical research organisations where the principles would impair their core activities
* Individual rights are limited where they can be abused to commit crimes, disrupt legal proceedings or otherwise disrupt public authorities and regulators

How well did you know this?
1
Not at all
2
3
4
5
Perfectly