Data Management Flashcards

1
Q

Difference between GDPR and Data Protection Act?

A
  • GDPR 2016 is an EU-wide data protection law. DPA 2018 is the UK’s implementation of the GDPR
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are the 7 principles of GDPR?

A
  • LP MASSA
  • Lawfulness processed lawfully
  • Purpose Limitation for the relevant purpose
  • Data Minimalisation adequate and not exessive
  • Accuracy held no longer than necessary
  • Storage Limitation accurate and up to date
  • Security not transferred to other countries without same security
  • Accountability kept securely
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What can you tell me about the GDPR/ DPA?

A
  • The UK’s implementation of GDPR. It is a complete data protection system and replaced the 1998 Act and relates to personal data. The obligations are more prescriptive and the penalties greater.
  • Policed by Information Commissioners Office (ICO)
  • Data breaches must be reported to ICO within 72 hours if they relate to personal data
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are the 8 individual rights under GDPR?

A
  1. Right to be informed
  2. Right of access
  3. Right to rectification
  4. Right to erasure
  5. Right to restrict processing
  6. Right to data portability
  7. Right to object
  8. Right to automated decision making and profiling
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

How do you keep data secure in your place of work?

A
  • A great deal of my work is undertaken reviewing confidential portfolio information for a retained banking client, I therefore ensure that the sensitive data that they share with me is kept in password protected documents and access to the folder in which the documents are saved is not shared beyond what is needed.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Tell me about the Freedom of Information Act 2000

A
  • Gives individuals the right to access information held by public bodies
  • Public body must tell any individual requesting sight of information whether it holds it
  • Normally the public body must supply requested info within 20 working days in the requested format
  • It can charge of the provision of the information
  • Exemptions include:
  • Contrary to GDPR requirements
  • It would prejudice a criminal investigation
  • It would prejudice a person/organisations commercial interest
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

who enforces data protection legislation in the uk

A

Information commissioners office

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q
A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly