Data Management Flashcards
What does GDPR stand for ?
General Data Protection Regulation (how we collect and process personal data)
When did GDPR come into affect ?
25 May 2018 (UK).
What are the maximum fines (UK GDPR) , how are the fines calculated?
• £17.5 million or 4% of the total annual worldwide turnover in the preceding financial year, whichever is higher
Have you completed any training on GDPR ? what did you learn ?
Yes, please see CPD.
What legislation covers data protection in the UK ?
Data Protection Act 2018 and UK GDPR
Who does Freedom of Information Act Apply to?
Public right of access to information held by public authorities.
Does GDPR apply post Brexit ?
Converted into UK Law on 1st Jan 2021 under the title UK GDPR.
What will the changes include (GDPR post Brexit)?
UK government will control the UK GDPR as opposed to the European union.
Who oversee information rights in the UK ?
ICO - Information Commissioners Office
What happens if you are sharing or processing data from the EU ?
Adhere to :
• UK GDPR
• EU GDPR
• Data Protection Act 2018
Who enforces the data protection ?
Information commissioners office - ICO
How do you ensure data you hold on clients is kept secure and confidential ?
1) Smart passwords/Firewalls/Anti-virus software.
2) Limit access to sensitive data.
3) Update security
What are the 7 GDPR principles? - LADSPAS
- Lawfulness, fairness and transparency – leave the individual fully informed
- Accuracy – where necessary kept up to date, erase inaccurate personal data without delay
- Data minimisation – collect the minimum data you need
- Storage limitation – Retain the data for a necessary limited period and then eras
- Purpose limitation – must inform your clients about the purpose of the data collection
- Accountability – Record and prove compliance
- Security - Integrity and confidentiality – Keep it secure, locked filing cabinet or fire wall
How have you changed the way you managed data during COVID 19 and home working ?
1) Only use work equipment
2) The storage of files/documents to be locked away,
3) Regular update on password protected equipment etc.
Why do you keep company data for 12 years?
PII insurance requirement (contracts under deed are kept for a minimum of 12 years and under hand for 6 years).
I am aware of the limitation act to claims which can be brought about up to 15 years after the act of negligence.
What is project extranet?
Network that allows controlled access from the outside for specific project purposes.