Data Management Level 1 Flashcards
What are the seven principles of GDPR?
- Fair, lawful and transparent processing
- Purpose limitation
- Data minimisation
- Accuracy
- Data retention periods
- Data security
- Accountability
What does GDPR concern? Who is responsible for GDPR?
Protects individuals from being identified in data.
Concerns information that allows a living person to be directly, indirectly identified from data that’s available.
Largely, GDPR places the most emphasis on data controllers and processors.
When did UK GDPR become effective?
1 January 2021
What is the freedom of information Act 2000?
Can request information from public bodies: government departments, local council, schools, public health services, police etc.
Does the public body have to provide information under FOI 2000?
Must be provided unless there is a good reason not to.
e.g. under investigation or is sensitive in nature.
How can the public gain access under FOI?
Requests are made under Subject Access Requests (SARs)
Must be responded to within 20 days of receipt
What is the Commissioner for Revenue and Customs Act 2005?
Section 10 of the Act gives the right to the VOA to conduct valuations
Section 18 of the Act allows HMRC to share information with the VOA to perform our statutory function.
How do you direct requests for information?
If a request for information comes directly to me, I first see if it can be dealt with within the team under legislation.
If not, I forward the request on to the subject access request team and inform my line manager.
What techniques do you use to save data?
- Electronic Data management system
- Check Challenge Appeal portal has public and internal document sections
- Save files on cloud based systems ensuring back up
- Save files in restricted/password protected folders.