Data Management Flashcards
Who regulates GDPR in the UK?
Information Commissioners Office
What are the keys persons outlined in GDPR?
Controller - decides how and why personal data is used
Processor - handles personal data on behalf of controller
Data officer - oversees data protection and ensures compliance
What is the purposes of GDPR?
Protects citizens information
What act implemented GDPR in the UK?
Data Protection Act 2018, replaced Data Protection Act 1998
What are the 7 principal of GDPR?
Lawfulness, transparency & fairness
Accountability
Accuracy
Purpose Limitation
Storage Limitation
Integrity & Confidentiality
Data minimisation
What are the 8 individual rights under GDPR?
Right to be informed
Right of Access
Right to Rectfication
Right to Forgotten (erasure)
Right to Restriction Processing
Right to Data Portability
Right to Object
Rights related to Automated Decision making and Profiling
Who does GDPR apply to?
Any and all business and organisations responsible for holding data.
What are the penalties for breaches to GDPR?
Fine of up to 17.5 million, or 4% of your annual turnover, whichever is higher
How and when should a breach of GDPR be notified?
Notify the Information Commissioners Office within 72 hours of the breach.
What are the obligations set out in GDPR?
The obligation to implement appropriate security measures, according to the risk involved in the data processing operations they perform.
Ensure data is accurate and kept up-to-date.
Only relevant data must be collected
Only store for as long as is necessary
What is a firewall?
An electronic protection system that prevents unauthorised access to the firms network and data. All incoming and outgoing messages have to pass through this.
What is included in your firms privacy notice?
Categories of data we process
Purposes for processing your data
Who has access to that data
How it is stored securely
How long we retain that data
Rights of the consumer
What is a subject access request?
The demand of an individual to be given all information a company holds under GDPR
What does the the Freedom of Information Act 2000 implement?
Individuals request personal information from PUBLIC bodies. Must be done within 20 days and can be charged for the admin.
How do you comply with GDPR in your role?
Report any suspected breaches
I do not share confidential or personal information
I keep consent for data processing