Data Management (Level 1 Portfolio) Flashcards
What is GDPR?
General Data Protection Regulation
What is GDPR for?
Legal framework to set guidance for the collection & processing of data
When did GDPR become introduced?
May 25 2018
What is the UKs implementation of GDPR?
Data Protection Act 2018
What does the Data Protection Act 2018 do?
It gives everyone responsibility for using personal data and has to follow strict data principles
What are the data protection principles?
Lawful, fair and transparent
Purpose limitation
Data minimisation
Accuracy
Storage limitation
Security
Accountability
What is the punishment for breaching GDPR?
20 million euros (around £17million) or 4% global annual turnover, which ever is greater
What has changed from 1998 to 2018?
The definition of data is up to date to include new technologies, such biometric.
Larger fines
Breaches must be reported in 72 hours
Clear privacy notices must be given to consumers
Orginisations must provide staff training and internal audits
Any company with over 250 employees or process over 5,000 subject profiles must have a data protection officer
What is information governance?
An approach to managing the way information is handled by setting out rules and managing the processes.
What are the aims of information governance?
To comply with legislation
Have an effective and appropriate use of information
Managed process for reporting and recording data issues
Provide staff training and support
Encourage staff to work together for effective data use
How do the council apply information governance?
We have set processes for using and collecting data such as the databse which has certain rules in place to keep it secure and accurate, we use it for effective data use for example when raising repairs it is a secure method to share customers details so appointments can be raised and work can be done.
What PCC polices manage data handling?
We have five policies, Data in Transit, Data Processor, Data Protection & Data Sharing & Records Management
What is a ROPA?
Record of Processing Activity, which is a legal duty to under GDPR and DPA 2018. For the council we use the Information Asset Register which outlines what information we may have and why we use it.
What does PCCs Data Protection Policy do?
It ensures that all employees and all third party members who have access to any personal data are fully aware of and abide by their duties and responsibilities under DPA and GDPR
What is the Freedom of Information Act 2000?
A piece of legislation that allows the public to access information help by public authorities.