Data breaches Flashcards
Requirements needed for person to be recruited to a DPO role
none
What year was GDPR introduced?
may 2018
Meaning of GDPR?
Generaldata protection regulation
Rights under GDPR?
- Right to access information
- Right to be informed
- Right to rectification
- Right to erasure
- Right to data portability
- Right to object to automated processing
- Right to object to processing of personal data
- Right of restriction
- Restriction of Individual Rights in certain circumstances
Data protection act 1998-2003 versus GDPR 2018
- Improved transparency, accountability and provisions for individuals’ rights, increased fining up to 20 million
- Establishing a new Data
Protection Commission
What happens if data protection complaint relates to an incident occurring before 2018?
the Data Protection Acts 1988
– 2003, and not the GDPR,
will apply
What is the formal procedure when requesting your own clinical notes from hospital?
As per rule 8 of data protection, how soon must a note be filed?
24 hours
How long after turning 18 are files destroyed?
Exception?
8 years
Exception:
- if treatment is completed at 17, 9 years
- if likely to have implications in the future
how many new cases were processed by DPC last year?
how many were valid breach notifications?
what % came from public/voluntary sector?
9300
5000
48%
When is a DPO required for a company?
- Done by a public authority or body.
- Involves regular and systematic monitoring of a large number of individuals.
- Involves large-scale processing of specific types of data, such as criminal records
For data protection impact assessments for new high-risk assessments, it’s necessary to…?
Mandatorily assess potential data protection risks.
Identify and address risks that may impact your organization or individuals involved.
Develop plans to implement solutions for mitigating these risks.
Evaluate the feasibility of the project at an early stage
What happened with Cambridge Analytical?
CA collected personal data on 87 million FB users in 2010s without their consent using a quiz ‘This is your Life’
Data used in Trump Campaign → target people who are prone to conspiratorial thinking
Accused of interfering with Brexit referendum
What is a data breach?
a security incident that unintentionally or unlawfully results in the accidental destruction, loss, alteration, unauthorized disclosure, or access to personal data that is being transmitted, stored, or processed.
fines for serious breach?
fines were extremely serious breach?
up to 10 million
up to 20 million