Data Management Flashcards
What is the Data Protection Act 2018?
- UK’s implementation of the General Data Protection Regulation 2016 (GDPR)
- Complete data protect system – as well as governing personal data covered by GDPR, it covers all other general data as previously covered by the 1998 Act
What is GDPR?
- General data protection regulation
- Relates to personal data
- Aims to create a single data protection regime for anyone doing business in the EU and to empower individuals to take control of how their data is used by third parties
- Gives people stronger rights to be informed about how their personal information is used
When did GDPR come into force?
May 2018
What are the key requirements under GDPR?
- Obligation to conduct data protection impact assessments for high risk holding of data
- New rights for individuals to have access to information on what personal data is held and to have it erased
- A data controller decides how and why personal data is processed and is directly responsible for GDPR
- ‘Data accountability’ ensuring that organisations can prove to the Information Commissioners Office (ICO) how they comply with the new regulations
What does Article 5(1) of GDPR state in relation to the processing of data?
Data must be processed lawfully, fairly and in a transparent manner in relation to individuals
What does Article 5(1) of GDPR state in relation to the collection of data?
Data must be collected or specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes
What does Article 5(1) of GDPR state in relation to the relevance of data?
Data must be adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed
What does Article 5(1) of GDPR state in relation to the accuracy of data?
Data must be accurate and, where necessary kept up to date; every reasonable step must be taken to ensure that personal data that are inaccurate, having regard to the purpose for which they are processed, are erased or rectified without delay
What does Article 5(1) of GDPR state in relation to the form which data is kept in?
Data must be kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed
What does Article 5(1) of GDPR state in relation to the the processing of data?
Processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisation measures
Who does Article 5(2) of GDPR state is responsible for the compliance with the principles outlined in Article 5(1)?
The data controller shall be responsible for, and be able to demonstrate compliance with the principles
What are the 8 individual Rights under GDPR?
AIRER POA
- Right of access
- Right to be informed
- Right to rectification
- Right to erasure
- Right to restrict processing
- Right to data portability (to use for their own purposes)
- Right to object
- Rights to automated decision making and profiling (as undertaken by insurance companies
What do you understand by the term security of data?
Means ensuring that data is kept safe from corruption and that access to it is suitably controlled to ensure privacy and protection
How can security of data be improved?
- Disk encryption - encrypting data on a secure hard disk drive
- Regular back ups off site
- Password protection
- Use of anti-virus software protection
- Firewalls and disaster recovery procedures
What does Crown Copyright cover?
All materials created and prepared by the Government, such as laws, public records, official press releases and OS mapping