Data Management Flashcards
1
Q
Difference between GDPR and Data Protection Act?
A
- GDPR 2016 is an EU-wide data protection law. DPA 2018 is the UK’s implementation of the GDPR
2
Q
What are the 7 principles of GDPR?
A
- LP MASSA
- Lawfulness processed lawfully
- Purpose Limitation for the relevant purpose
- Data Minimalisation adequate and not exessive
- Accuracy held no longer than necessary
- Storage Limitation accurate and up to date
- Security not transferred to other countries without same security
- Accountability kept securely
3
Q
What can you tell me about the GDPR/ DPA?
A
- The UK’s implementation of GDPR. It is a complete data protection system and replaced the 1998 Act and relates to personal data. The obligations are more prescriptive and the penalties greater.
- Policed by Information Commissioners Office (ICO)
- Data breaches must be reported to ICO within 72 hours if they relate to personal data
4
Q
What are the 8 individual rights under GDPR?
A
- Right to be informed
- Right of access
- Right to rectification
- Right to erasure
- Right to restrict processing
- Right to data portability
- Right to object
- Right to automated decision making and profiling
5
Q
How do you keep data secure in your place of work?
A
- A great deal of my work is undertaken reviewing confidential portfolio information for a retained banking client, I therefore ensure that the sensitive data that they share with me is kept in password protected documents and access to the folder in which the documents are saved is not shared beyond what is needed.
6
Q
Tell me about the Freedom of Information Act 2000
A
- Gives individuals the right to access information held by public bodies
- Public body must tell any individual requesting sight of information whether it holds it
- Normally the public body must supply requested info within 20 working days in the requested format
- It can charge of the provision of the information
- Exemptions include:
- Contrary to GDPR requirements
- It would prejudice a criminal investigation
- It would prejudice a person/organisations commercial interest
7
Q
who enforces data protection legislation in the uk
A
Information commissioners office
8
Q
A