Data Management (Level 1 Portfolio) Flashcards

1
Q

What is GDPR?

A

General Data Protection Regulation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is GDPR for?

A

Legal framework to set guidance for the collection & processing of data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

When did GDPR become introduced?

A

May 25 2018

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is the UKs implementation of GDPR?

A

Data Protection Act 2018

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What does the Data Protection Act 2018 do?

A

It gives everyone responsibility for using personal data and has to follow strict data principles

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What are the data protection principles?

A

Lawful, fair and transparent
Purpose limitation
Data minimisation
Accuracy
Storage limitation
Security
Accountability

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is the punishment for breaching GDPR?

A

20 million euros (around £17million) or 4% global annual turnover, which ever is greater

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What has changed from 1998 to 2018?

A

The definition of data is up to date to include new technologies, such biometric.
Larger fines
Breaches must be reported in 72 hours
Clear privacy notices must be given to consumers
Orginisations must provide staff training and internal audits
Any company with over 250 employees or process over 5,000 subject profiles must have a data protection officer

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is information governance?

A

An approach to managing the way information is handled by setting out rules and managing the processes.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What are the aims of information governance?

A

To comply with legislation
Have an effective and appropriate use of information
Managed process for reporting and recording data issues
Provide staff training and support
Encourage staff to work together for effective data use

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

How do the council apply information governance?

A

We have set processes for using and collecting data such as the databse which has certain rules in place to keep it secure and accurate, we use it for effective data use for example when raising repairs it is a secure method to share customers details so appointments can be raised and work can be done.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What PCC polices manage data handling?

A

We have five policies, Data in Transit, Data Processor, Data Protection & Data Sharing & Records Management

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is a ROPA?

A

Record of Processing Activity, which is a legal duty to under GDPR and DPA 2018. For the council we use the Information Asset Register which outlines what information we may have and why we use it.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What does PCCs Data Protection Policy do?

A

It ensures that all employees and all third party members who have access to any personal data are fully aware of and abide by their duties and responsibilities under DPA and GDPR

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is the Freedom of Information Act 2000?

A

A piece of legislation that allows the public to access information help by public authorities.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What are some key points of the FoI to remember?

A

Affects all staff regarding what information we create, hold and delete.
Anybody can ask for information and PCC must disclose information if it is necessary within 20 days (by law)
Must forward requests to the FoI team ASAP
Requests must be in writing
All information could be disclosed such as emails & documents
If anyone alters data after a request it is a criminal offence with a fine up to £5000

17
Q

How do PCC adhere to secure information?

A

Fire walls, virus protection and spyware detection
Laptop encryption
Regular backups of data
Network access management
Email & website filtering
Provide advice and guidance

18
Q

What are PCCs key aims of protection of information?

A

Confidentiality - controlled acess
Integrity - no unautherised changes
Availability - continuously available
Compliance - follow policies and laws

19
Q

What is the Information Commissioners Office?

A

ICO is a third party individual organisation that upholds information rights for the public

They look at complaints for potential for breaching GDPR/DPA

20
Q

Have PCC had any data breaches?

A

Over the last 5 years or so the council have reported 13 incidents and 12 of which the ICO decided no futher actioj was needed as we were following GDPR/DPA properly, the one undecided in Nov 2019 i couldnt find an asnwer.

21
Q

What data do you collect in your day to day job?

A

For repairs, names & numbers.

Use the database to store the data securely into the correct boxes to allow for availability and for it to be deleted / redacted.

22
Q

What could be consequences to you (me as an emplyee) for breaching GDPR?

A

Verbal or written discaplinary actions
Legal consequences
Loss of job

23
Q

When can a FoI request be denied?

A

When it takes too much time
When it costs too much
If it is a repeat request by the same person
If the request is vaxatious (cause annoyance/frustration)

24
Q

What is a subject access request?

A

When you send a written request to an orginisation for any personal information they hold on you.