Data Management Flashcards
What does the Data Protection act (2018) cover?
The Data Protection Act 2018 is the UK implementation of the GDPR.
Controls how personal information can be used and your rights to ask for information about yourself
Sets out the need to use information;
- Fairly
- Lawfully
- Transparently
How do you comply with GDPR and the Data Protection Act 2018 in your role/ when using Landstack, Costar etc?
- Ensure access to data is only granted to people who require it
- I ensure that all files and folders are labelled correctly.
- Data is only stored for as long as necessary – either for the length of time needed for a project or to comply with statutory regulations e.g money laundering
- Secure confidential and sensitive information with password encryption
- Only share data using secure systems
How do you validate information?
Source – is the source credible and reliable
Time – how recent is the information gathered is it as up to date as possible
Relevance – is the information gather directly related to your need or purpose
Sense check – try to verify the information by cross referencing
What are the penalties for breach of GDPR?
Fined up to 4% of annual global turnover or 17.5million euros
What are the ways you can manage data?
Excel/outlook
How long should files be kept for?
No longer than required.
6 years from end of relationship with client.
What is the freedom of information act?
- Gives individuals right of access to info held by public bodies
- Public body must tell any individual requesting sight of info whether it hold it.
- Public body must reply within 20 working days
- It can charge for the provision of the info
How can the security of the electronic data be improved?
Firewalls, encryption and passwords
What is a firewall?
A software that blocks unexpected connections coming into or out of the network.
Who deals with GDPR internally?
Data protection officer
What are your individual rights under GDPR?
- Rights to informed
- Rights to access
- Rights to rectification
- Rights to erasure
- Rights ti restrict processing
- Right to data portability
- Right to object
- Right to automated decision making and profiling
What are the principles of the UK GDPR?
States that data must be
- Processed lawfully, fairly and in a transparent manner
- Collected for specified, legitimate purposes
- Limited to what is necessary
- Data that is inaccurate/out of date mist be erased
- Kept for no longer than necessary required
- Processed in a manner that ensures appropriate security of the personal data
Who deals with GDPR externally?
ICO report within 72 hours
What is GDPR?
General Data Protection Regulation 2016 came into effect across the whole of the EU to control how personal information is used.
Now that we have left the EU, the UK’s GDPR implementation is the Data Protection Act 2018
What are they key requirements under the Data Protection Act 2018?
- An obligation to conduct data impact assessments for high risk holding of data
- New rights for individuals to have access to information on what personal data is held and to have it erased
- A data controller decides how and why personal data is processed and is directly responsible for GDPR
- A new principle of data accountability ensuring that organisations can prove to the ICO how they comply with the new regulations
- Data security breaches need to reported to the ICO within 72 hours whether there is a loss of personal data and a risk to harm to induvial
An increase of fines up to 4% global turnover of the company or 20 million euros (whichever is highest)