Data management Flashcards
What is GDPR
General Data Protection Regulation
What is GDPR for?
Its a legal framework that set guidance for the collection and processing of personal data
When was GDPR introduced?
25 May 2018
What is the Data Protection Act 2018?
UK’s implementation of GDPR, it makes everyone in the UK responsible for using personal data and have to follow strict rules called the data protection principles
What are the seven data protection principles?
‘Long Purple Dresses Always Seem Stupid Anyway’
Lawful, fair and transparent Purpose limitation Data minimisation Accuracy Storage limitaion Security Accountabilty
What is the UK’s implementation of GDPR?
The Data Protection Act 2018
What is the punishment dor breaching GDPR?
20 million euros or 4% global turnover, whichever is greater
What changed from data protection act 1998 to now?
Definition if data to include new technology such as biometric data
Clear privacy notices must be given to consumers
Breaches have to be reported in 72 hours
Larger fines
Sufficient training is mandatory to be in place
Any company with more than 250 employees need a data protection officer or deal with over 5000 subject profiles a year
What is information governance?
The approach to managing the way thay information is handled - particulary personal data that relates to identifying people.
It balances the risk information presents and the value that it provides.
What is the aim of Information Governance?
To comply with legislation
Have an effective and appropriate use of information
A managed process for reporting and recording data security issues
Provide training and support to staff
Encourage staff to work together for efficient data use
What is the Freedom of Information Act 2000?
Provides public access to information held by public authorities, it covers all information held such as documents, emails, letters
What does the councils freedom of information policy ensure?
Comply with FOI to enhance public trust and confidence
20 days to respond to requests
Follow GDPR and DPA with data handling
Provide assistance with requests
Ensure all staff dealing with data are aware of obligations under FOI
How do PCC keep data secure?
Firewalls, virus protection and spyware detection Laptop encryption Regular backups of data Network access management Email & website filtering Advice & guidance
PCC key aims for protecting information are…
Confidentiality, integrity, availability and compliance
What is the ICO?
Information Commissioner Office