Data Management Flashcards

1
Q

Who regulates GDPR in the UK?

A

Information Commissioners Office

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are the keys persons outlined in GDPR?

A

Controller - decides how and why personal data is used
Processor - handles personal data on behalf of controller
Data officer - oversees data protection and ensures compliance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is the purposes of GDPR?

A

Protects citizens information

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What act implemented GDPR in the UK?

A

Data Protection Act 2018, replaced Data Protection Act 1998

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are the 7 principal of GDPR?

A

Lawfulness, transparency & fairness
Accountability
Accuracy
Purpose Limitation
Storage Limitation
Integrity & Confidentiality
Data minimisation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What are the 8 individual rights under GDPR?

A

Right to be informed
Right of Access
Right to Rectfication
Right to Forgotten (erasure)
Right to Restriction Processing
Right to Data Portability
Right to Object
Rights related to Automated Decision making and Profiling

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Who does GDPR apply to?

A

Any and all business and organisations responsible for holding data.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What are the penalties for breaches to GDPR?

A

Fine of up to 17.5 million, or 4% of your annual turnover, whichever is higher

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

How and when should a breach of GDPR be notified?

A

Notify the Information Commissioners Office within 72 hours of the breach.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What are the obligations set out in GDPR?

A

The obligation to implement appropriate security measures, according to the risk involved in the data processing operations they perform.
Ensure data is accurate and kept up-to-date.
Only relevant data must be collected
Only store for as long as is necessary

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is a firewall?

A

An electronic protection system that prevents unauthorised access to the firms network and data. All incoming and outgoing messages have to pass through this.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is included in your firms privacy notice?

A

Categories of data we process
Purposes for processing your data
Who has access to that data
How it is stored securely
How long we retain that data
Rights of the consumer

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is a subject access request?

A

The demand of an individual to be given all information a company holds under GDPR

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What does the the Freedom of Information Act 2000 implement?

A

Individuals request personal information from PUBLIC bodies. Must be done within 20 days and can be charged for the admin.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

How do you comply with GDPR in your role?

A

Report any suspected breaches
I do not share confidential or personal information
I keep consent for data processing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

How long should you retain files?

A

6 years after the relationship expires, as legal action can be bought forward within this timeframe (Limitations Act 1980)

17
Q

What does your firm use to store data?

A

an Electronic Document Management System (Sharepoint)

18
Q

How do you ensure GDPR compliance and security in the office?

A

Clear desk policy
Shred any files with confidential information
Lock screen
Password protect
External back-up

19
Q

What would you do if you received confidential information that your should not have seen?

A

Do not use it
Report to DCO and compliance office
Advise the client or sender of error
Dispose of the information securely and properly

20
Q

What are the exemptions to Data Protection Act 2018?

A

National Security
Law enforcement
Public health

21
Q

What are the benefits of Cloud based storage systems?

A

Information is backed up securely on encrypted servers
Accessibility can be managed via online settings
Cloud is often cheaper than the cost of storing physical files
It is more convenient to send electronic files than mailing physical files
Cloud systems are more environmentally friendly
Multiple users can assess the same document at once.

22
Q

What is an NDA?

A

Non- disclosure agreement
Used to protect against disclosure or sharing of confidential data

23
Q

Who are the key persons outlined in GDPR?

A

Controller - person or entity that determines the purposes of the processing of data (BM)
Processor - the person who processes that information (could be me)
DPO (Data protection officer) - leadership role required within companies that process personal data of EU citizens and is responsible for overseeing the data protection approach, strategy and implementation.

24
Q

What are the 8 individual rights under GDPR?

A
  • right to be informed (of how data is used)
  • right of access (know exactly what information is held and how it is being processed)
  • the right to rectification (correction)
  • right to erasure (removal without any specific reason)
  • right to restrict processing
  • right to data portability (allows individuals to retain and reuse data for own purpose)
  • right to object
  • right to automated decision making and profiling
25
Q

What things must companies put in place to ensure GDPR compliance?

A

Raise awareness across the business
Audit all personal data held
Update Privacy notice
Review procedures to support the 8 rights
Identify and document the legal basis for processing personal data under GDPR
Review how we seek, obtain and record consent