Data Management Flashcards
1
Q
What is the difference between the Data Protection Act 1998 and updated 2018 Act?
A
The main difference is that the Data Protection Act incorporates GDPR (General Data Protection Regulations as provided by the EU) into UK statue. The key principles within the 2018 Act are very similar to those in the 1998 Act. The new principles are:
- Fairness, lawfulness and transparency
- Limitation of purpose
- Minimisation of data
- Accuracy
- Period of data retention
- Data security
- Accountability
2
Q
What is GDPR?
A
GDPR is the EU General Data Protection Regulations, which came into enforce in May 2018. They govern personal data, and apply to all companies holding personal data that act within the EU. Key principles:
- Consent (explicit consent) is required to gather personal data
- You must delete personal data you are no longer using for its original purpose
- People can revoke their consent, and you must comply
- You have 72hour to notify a data breach
- You need a Data Protection Officer