Data Management Flashcards

1
Q

How can you comply with UK GDPR when dealing with mailing lists?

A
  • Only collect information that is required
  • Ensure that is very clear that there are ways to unsubscribe
  • Ensure you get consent from partipants to be on the mailing list
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What sorts of information a firm can reasonably retain in order to comply with other laws?

A

CHECKKK

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What Data Management Training have you undertaken?

A
  • Password Protection Training
  • Clear desk policy
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What systems does Cluttons have in place to ensure data security?

A
  • Firewalls
  • Encryption
  • Regular password updates
  • Two-Factor Authentication
  • Anti-virus software

CHECK

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Who is UK GDPR policed by?

A

Information Commissioner’s Office (ICO)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What are the fines for non-compliance for GDPR?

A

Fines of up to 4% of global turnover of the company or £17.5 million (which ever is greater)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What are the individual rights under UK GDPR?
(submission)

A
  1. Right to be informed
  2. Right of access
  3. Right to rectification
  4. Right to erasure
  5. Right to restrict processing
  6. Right to data portability (to use for their own purposes)
  7. Right to object
  8. Right to automated decision making and profiling (as undertaken by insurance companies)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What does the Freedom of Information Act (2000) outline?

A
  • Gives individuals the right of access to information held by public bodies
  • The public body must tell any individual requesting sight of information whether it holds it
  • Normally the public body is required to supply it in 20 working days in the format requested
  • It can charge for the provision of the information
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What exemptions are allowed under Freedom of Information Act 2000?

A

Contrary to the GDPR requirements

It would prejudice a criminal matter under investigation or a persons/organisations commercial interest

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

How can security of data be improved?

A

Using firewalls, encryption and strong passwords

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is Crown Copyright?

A

All material created and prepared by the Government e.g. Laws & OS Mapping

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is copyright?

A

A set of exclusive rights granted to the author or creator of any original work, including the right to copy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Does the EU’s GDPR apply in the UK?

A

NO - but EU’s GDPR’s was almost entirely transcribed into UK GDPR

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is UK GDPR supplemented by?

A

Data Protection Act 2018

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is the Data Protection Act 2018?

A

Controls how your personal information is used by organisations, businesses or the government.

It gives individuals the right to access their own personal data through subject access requests and contains rules which must be followed when personal data is processed.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What are the key requirements of the DM & GDPR? CHECK

A
  • An obligation to conduct data protection impact assessments for high risk holding of data
  • New rights for individuals to have access to information on what personal data is held and to have it erased
  • A data controller decides how + why personal data is processed + is directly responsible for GDPR
  • A new principle of ‘data accountability’ = organisations can prove to the ICO how they comply with the new regulations
  • Data security breaches need to be reported to ICO within 72 hours where there is a loss of personal data + a risk of harm to individuals
  • Fines to up 4% of global turnover of the company or £17.5million (whichever is the greater)
  • Policed by the ICO
17
Q

When do data security breaches need to be reported by and who do you report them to?

A
  • Within 72 hours where there is a loss of personal data + risk of harm to inviduals
  • Report to ICO
18
Q

What is ISMS?

A

Information Security Management System

19
Q

What data security training have you undertaken?

A
  • Regular online information security training – KnowBe4 – 2023 Common threats, Internet threats, Your Role in Information Security
  • Acceptable IT Use Policy
  • Mobile Device Policy
  • Information Security Policy
  • Phishing Emails
20
Q

Why is that information you handle valuable?

A

Identity theft, fraud, cyber attacks,

21
Q

What does Cluttons do to keep you informed about information security issues?

A
  • Regular emails
  • staff online training
  • Updates to firm policies
22
Q

How do you ensure that data is stored correctly?

A
  • Use strong passwords and two-factor authentication
  • Ensure a back up your data
  • Keep users groups list up to date

CHECK

23
Q

What are the key principles of UK GDPR?

A

Article 5 of the UK GDPR sets out seven key principles which lie at the heart of the general data protection regime.

The UK GDPR sets out seven key principles:
1. Lawfulness, fairness and transparency
2. Purpose limitation
3. Data minimisation
4. Accuracy
5. Storage limitation
6. Integrity and confidentiality (security)
7. Accountability