Data Management Flashcards
How do you set up a data room and ensure its security?
Data room is a secure data sharing platform used to store clients files
- Select file provide.
- Create firewall / security wall
- Upload client files
- Provide access to relevant personnel
What are some of the principles of GDPR?
Outlined in Article 5:
Data must be:
- Processed LAWFULLY, FAIRLY and in a TRANSPARENT manner.
- Collected for LEGITIMATE and SPECIFIC purposes
- KEPT UP TO DATE
- Kept in a form which permits identification of data subjects for NO LONGER THAN NECESSARY
- Processed in a manner that ensures SECURITY.
- INCORRECT DATA to be erased or rectified without delay
What individual rights under UK GDPR?
The right to be informed
The right to access
The right to object
The right to erasure and blocking
The right to rectify
The right to file a complaint
The right to damages
The right to data portability.
What is Copyright?
- Exclusive rights granted to the creator of original work, including rights to copy.
- Rights can be licensed, assigned or transferred.
- Form of intellectual property.
- Individuals need to acknowledge any copyright for information duplicated in your work.
What is the UK Data Protection Act 2018?
Applies data protection standards set out by EU GDPR.
Sets the provisions for processing personal data giving individuals the right to be informed about how their personal information is used by third parties.
What are the fines associated for data breaches?
Firms can be fined up to 4% of global turnover or £17.5 million (whichever is greater).
Who should data security breaches be reported to?
ICO - Information Commissioner’s Office
When do data breaches need to be reported?
Within 72 hours of the breach, where there is a loss of personal data and risk of harm to individuals
What should you do if you breach GDPR?
- Inform line manager and compliance officer
- Request the recipient of the information disposes of it securely.
- Inform client of the breach
- Report to ICO
What are the key requirements of the Data Protection Act 2018?
- Obligation to conduct date protection impact assessments.
- New rights for individuals to have access to information and have it erased.
- New principle of ‘data accountability’ - organisation must prove how they comply with new regulations.
What is an NDA?
Non-disclosure agreement
Legally binding contract that establishes a confidential relationship and protects the information, they share from being disclosed to outsiders.
What gives individuals rights to access information held by public bodies?
Freedom of Information Act 2000
What do you understand about the Freedom of Information Act 2000?
- Public body must say to individual requesting sight of information whether they hold it
- Public body required to provide this information in 20 days
- It can charge for the provision of the information
When would there be exemptions to this?
- If GDPR is breached
- It would prejudice a criminal matter under investigation