Data Management Flashcards
What are the 8 Principles of GDPR?
Fair and Lawful Specific for its purpose Be accurate and up to date Not kept longer than needed Take into account other peoples rights Kept safe and secure No transferred outside the EEA.
LPRATSA Lawful Purpose Relevant Accurate Time Secure Accountable
How long should files be kept for?
12 Years
How long can personal files be kept for?
Up to 6 years
What is GDPR?
Data Protection Act 1998 brought in to cover modern data and technology.
Following leaving the EU, the data protection act was amended to incorporate the new legislation.
What are the principles of GDPR/Data Protection Act?
◼ Information used lawfully, fairly and transparently
◼ Collected for specified, explicit and legitimate purposes
◼ Adequate, relevant and limited to necessity
◼ Accurate (kept up to date)
◼ Kept no longer than necessary
◼ Kept safe
What are an individuals rights under GDPR/DPA?
◼ To be informed ◼ To access ◼ To rectification ◼ To erasure ◼ To restrict processing ◼ To data portability ◼ To object ◼ To automated decision making & profiling
What are the penalties for not following the GDPR/DPA?
◼ Fines (4% of annual global turnover or 20 million euros)
What is the purpose of the ISO 9001:2015?
◼ Sets the requirements on how firms should control data and documents relevant to
the service they provide.
◼ Sets requirements for a company’s Quality Management System (QMS), which is
about the management of the entire enterprise and its operational processes.
What is the Freedom of Information Act 2000?
- Act of Parliament that creates a public “right of access” to information
held by public authorities. - There are exemptions.
Give me some examples of the principles of good data management.
Avoid recollecting data Data Lifecycle control Data Policy Data ownership Metadata Data Quality Data Audit
Which body is responsible for enforcing the GDPR?
The Information Commissioner’s Office (ICO)
What does the Freedom of Information Act enable?
The Freedom of Information Act 2000 provides public access to information held by public authorities. It does this in two ways: public authorities are obliged to publish certain information about their activities; and members of the public are entitled to request information from public authorities.
How do you ensure the data that you hold on your clients is kept secure and confidential?
Limit access for those on a need to know basis.
How do you ensure the data that you hold on your clients is kept secure and confidential?
We have a password system
How long do you keep client’s data and how do you ensure it is deleted when necessary?
6 years
Keep records on when data is collected