Data management Flashcards
What legislation covers data protection?
General Data Protection Regulation (GDPR)
In the UK, the Data Protection Act 2018 (DPA) covers processing that does not fall within EU law, for example relating to immigration and national security.
What is the Data Protection Act?
Controls how your personal information is used by organisations, businesses or the government
When did GDPR come into affect?
25 May 2018
Have you completed any training on GRPR?
Yes. We have to undertake mandatory GDPR training every two years.
What data does your company have?
- Details of current, past and prospective employees, clients, suppliers and others that we communicate with.
- Tenants
What is personal data?
Personal data means any information relating to an identified or identifiable natural person (‘data subject’);
An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person; (Source: Article 4 GDPR)
Who ensures compliance?
Nominated Data Protection Officer (DPO)
The DPO is supported by a core team who provide assistance with a number of different areas relating to the protection of information and who can help with queries.
Who does Freedom of Information Act Apply to?
Public right of access to information held by public authorities.
Does GDPR apply post Brexit?
Yes, many aspects of GDPR will be converted into UK Law on 1st Jan 2021 under the titles UK GDPR. in turn companies will still need to comply? Double check this.
What are the maximum fines (UK GDPR), how are the fines calculated?
£17.5 million
or 4% of the total annual worldwide turnover in the preceding financial year, whichever is higher.
What 10 tips to ensure compliance with GDPR?
- Prepare diligently to ensure compliance
- Assess any privacy risks inherent in business processes/activities
- Involve IT support to make appropriate changes
- Provide staff training and support on data security
- Appoint a Data Protection Officer if required by GDPR
- Ensure you have adequate systems to deal with a breach and subsequent notification to the ICO (within 72 hours)
- Do your systems comply with all GDPR principles, including the right to be forgotten
- Update your internet security, e.g. virus protection, including on desktops, laptops and mobile phones
- Ensure any data already held is up to date and compliant with GDPR
- Can you release personal data promptly if a subject access request is made?
Who oversee information rights in the UK?
ICO - Information Commissioners Office
How do you ensure data you hold on clients is kept secure and confidential?
- I use secure documents that are stored on password protected machines and servers.
- I also only keep the information I need and use it for the purpose it has been collected without passing it on unless I have approval prior.
What are the 7 GDPR principles? -
(LFT-A-DM-SL-PL-A-S)
- Lawfulness, fairness and transparency – leave the individual fully informed
- Accuracy – where necessary kept up to date, erase inaccurate personal data without dela
- Data minimisation – collect the minimum data you need
- Storage limitation – Retain the data for a necessary limited period and then eras
- Purpose limitation – must inform your clients about the purpose of the data collection
- Accountability – Record and prove compliance
- Security - Integrity and confidentiality – Keep it secure, locked filing cabinet or fire wall
How have you changed the way you managed data during COVID-19 and home working?
- No paperwork/documents
- Only use work equipment
- Regular password changes
How do DPA and GDPR differ?
Accountability to ensure that data is kept in accordance with the principles of GDPR
Tougher penalties for non-compliance
Wider definition of personal data
Non-EU organisations holding EU-related personal data will need to comply
Parental consent required for holding personal data of <16s
Active consent must be required to hold data, i.e. silence does not equal consent
Data breaches must be notified to ICO within 72 hours of awareness, unless exceptional circumstances apply
Risk-based reviews (Privacy Impact Assessments) must be undertaken for high risk activities
Right to be forgotten introduced
Requirements for electronic data portability if a data request is submitted
Compliance/privacy by design must be included within systems and processes, including staff training and contractual clauses
Additional liabilities placed on both data controllers and processors