Data Management Flashcards
How can you comply with UK GDPR when dealing with mailing lists?
- Only collect information that is required
- Ensure that is very clear that there are ways to unsubscribe
- Ensure you get consent from partipants to be on the mailing list
What sorts of information a firm can reasonably retain in order to comply with other laws?
CHECKKK
What Data Management Training have you undertaken?
- Password Protection Training
- Clear desk policy
What systems does Cluttons have in place to ensure data security?
- Firewalls
- Encryption
- Regular password updates
- Two-Factor Authentication
- Anti-virus software
CHECK
Who is UK GDPR policed by?
Information Commissioner’s Office (ICO)
What are the fines for non-compliance for GDPR?
Fines of up to 4% of global turnover of the company or £17.5 million (which ever is greater)
What are the individual rights under UK GDPR?
(submission)
- Right to be informed
- Right of access
- Right to rectification
- Right to erasure
- Right to restrict processing
- Right to data portability (to use for their own purposes)
- Right to object
- Right to automated decision making and profiling (as undertaken by insurance companies)
What does the Freedom of Information Act (2000) outline?
- Gives individuals the right of access to information held by public bodies
- The public body must tell any individual requesting sight of information whether it holds it
- Normally the public body is required to supply it in 20 working days in the format requested
- It can charge for the provision of the information
What exemptions are allowed under Freedom of Information Act 2000?
Contrary to the GDPR requirements
It would prejudice a criminal matter under investigation or a persons/organisations commercial interest
How can security of data be improved?
Using firewalls, encryption and strong passwords
What is Crown Copyright?
All material created and prepared by the Government e.g. Laws & OS Mapping
What is copyright?
A set of exclusive rights granted to the author or creator of any original work, including the right to copy
Does the EU’s GDPR apply in the UK?
NO - but EU’s GDPR’s was almost entirely transcribed into UK GDPR
What is UK GDPR supplemented by?
Data Protection Act 2018
What is the Data Protection Act 2018?
Controls how your personal information is used by organisations, businesses or the government.
It gives individuals the right to access their own personal data through subject access requests and contains rules which must be followed when personal data is processed.