Chapter 3 - Data Protection Flashcards
What are the 4 aspects covered by the Data Protection Act 2018 that is not covered by GDPR?
- Data processing for immigration
- Data processing for intelligence agencies
- Data processing for law enforcement
- Powers and duties of the ICO
What are the 6 data protection principles?
- Fair and lawful
- Purpose to be explicit and legitimate + specified
- Data to be adequate, relevant and not excessive
- Data to be accurate
- Data to not retained longer than necessary
- Data to be processed securely.
What is the max civil penalty the ICO can issue?
£500,000
What is the max criminal penalty the ICO can issue?
Unlimited fine
For how long must records of MiFID business be retained?
5 years
For how long must records of non-MiFID business be retained?
3 years however, FCA rules have specific record keeping requirements
Where are the FCA record keeping requirements set out?
SYSC
What is the scope of GDPR?
Covers data controllers and processors. Includes non-EU data processors/controllers who are handling the personal data of EU citizens.
What are the 7 principles of GDPR?
- Lawfulness
- Fairness + Transparency
- Purpose limitation
- Data minimisation
- Accuracy
- Storage limitation
- Accountability
What are the penalties that can be imposed by GDPR?
4% of annual global turnover (or €20,000,000 if greater) or
2% of annual global turnover (or €10,000,000 if greater).