Data Management (L2) Flashcards
What is GDPR?
(submission L1)
General Data Protection Regulation
What does the Data Protection Act 2018 do?
(submission L1)
The Data Protection Act 2018 is the UK’s implementation of the General Data Protection Regulation (GDPR).
What does GDPR do?
(submission L1)
Aims to create single data protection regime affecting businesses, and empower individuals to take control of how their data is used by third parties.
Gives people rights to be informed about how their personal information is used.
What are the 8 individual Rights under UK GDPR:
(submission L1)
- To be informed
- To access
- To rectification
- To erasure
- To restrict processing
- To data portability
- To object
- To automated decision making & profiling
What are the principles of GDPR and DPA (6 Key Points)
(submission L1)
- Information used lawfully, fairly and transparently
- Collected for specified, explicit and legitimate purposes
- Adequate, relevant and limited to necessity
- Accurate (kept up to date)
- Kept no longer than necessary
- Kept safe
What is the maximum penalty for a breach in the Data Protection Act 2018 / GDPR? (think companies not individuals)
Fines - 4% of global turnover or £17.5m (whichever is higher)
Who is UK GDPR policed by?
Information Commissioner’s Office (ICO)
What are the main differences between EU GDPR and UK GDPR?
Age of consent (13 in UK, 16 in Europe)
Fines (£17.5m in UK, 20m euros in Europe)
What constitutes personal data?
Any data relating to a natural person which can be used to directly or indirectly identify them.
What are the THREE key categories of people under GDPR?
Data Controller
Data Processor
Data Protection Officer
What are the three key categories of people under GDPR?
Controller - the entity responsible for determining the purpose and means of processing personal data.
Note - can also be a joint controller - i.e. an RICS Regulated managing agent with leaseholders information is bound by the RICS Professional Regulations and so is a joint controller.
Processor - an entity with responsibility for processing personal data under instruction from the Controller.
Data processors do not have the same level of GDPR compliance responsibilities as controllers.
Controllers have the strictest level of responsibility for GDPR. Note - employees are treated as agents for the controller.
Data Protection Officer - internal person required within public authorities or organisations who regularly process data, or sensitive data
How would you class your firm under GDPR terms?
Both Data Controller and Data Processor
My firms Data controller holds personal data for the firm’s employees.
My firm processes data under instructions of clients (the controller).
In a data security breach, what would you do?
- Inform the person’s whose data has been leaked
- Report to the ‘Information Commissioners Office’ (ICO) within 72 hours
How do you keep data secure in your job?
My firm uses firewalls, encryption and passwords.
How can you comply with UK GDPR when dealing with mailing lists?
Only collect information that is required
Ensure that is very clear that there are ways to unsubscribe
Ensure you get consent from participants to be on the mailing list