Data Management Level 2 Flashcards

1
Q

What is Personal Data?

A

Information that can be used to identify someone

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is GDPR?

A

General Data Protection Regulation, or UK GDPR (Data Protection Act 2018)

  • To give more control over your information.
  • sets new standards for protecting personal data in the UK. It revolves around placing stricter limitations on the amount and type of data that organisations
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is a data subject?

A

Person the data relates to.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is a data controller?

A

A person or business that decides how personal data is collected and determines what information is needed and why.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is a data processor?

A

A business or sole trader that handles data and personal information on the instructions of another party.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is the Information Commissioner’s Office?

A
  • responsible for legislation relating to data protection.
  • They enforce information rules and rights as well as data protection laws.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What are the senior management team (SMT), directors, and councillors responsible for in FG?

A

They authorise the publication of policies, procedures and annual training for all staff on compliance issues

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is your line manager responsible for?

A

Overseeing how personal data is handled within the department.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Who has a responsibility within your firm for protecting data?

A

Everyone has a collective responsibility.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is data minimisation?

A

Data should be adequate, relevant and limited to what is necessary, in relation to the purposes for which it is processed.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

How long should data be stored?

A

6 - 15 years

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is a privacy notice?

A

explains their information rights.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is erasure?

A

“the right to be forgotten”, the right to the erasure of records means that, in certain circumstances, and if the request is reasonable, people can approach organisations and ask the organisation to remove the information they have on them.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is portability?

A
  • means transferring data from one provider to another.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is Object to Processing ?

A
  • for direct marketing purposes
  • by automated means which have a significant impact.
  • on the grounds that a data subject’s rights outweigh the legitimate interest of an organisation that continues to process their data.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What does it mean to Restrict processing?

A

You have the right to restrict an organisation’s data processing procedure when it comes to your own personal data.

17
Q

What is a “Subject Access Request”?

A

SAR
- A request to see any records that relate to them.
Process - discuss with party what information they require before formal response.

1 CALENDAR MONTH TO RESPOND TO A FORMAL SAR.

18
Q

What is a freedom of information request?

A
  • requests directed towards an organisation and their workings rather than relating to the subject themselves.
  • includes information about the organisation’s policies, procedures, strategies and operations.

The Freedom of Information Act 2000

19
Q

How do you respond to a FOI?

A
  • check whether the requested information is covered under the Publications Scheme
  • If not, refer to line manager or DPO.
  • If you’re asked to help compile information to respond to a FOI request, remember that no personal data should be included.
20
Q

What is information security?

A

The protection from a loss of confidentiality, integrity and availability.

21
Q

What are the GDPR Rights?

A
  • Right to be informed
  • Right of access
  • Right to rectification
  • Right to erasure
  • Right to restrict processing
  • Right to Data portability
  • Right to Object
  • Rights in relation to automated decision making and profiling
22
Q

Process for a data breach?

A
  • Inform Data protection officer (Clare Phillipson)
  • Report to the Information Commissioners Office within 72 hours
  • High risk - inform individuals without undue delay
  • Ensure robust detection, investigation and internal reporting procedures in place.
  • Keep record of any personal data breaches.
23
Q

What is FGs Data Protection Policy?

A
  • In place to ensure we process all personal data in accordance with data protection laws.
  • Protect individual rights with regards to personal data.
  • Data protection training and procedures.
  • Continuous programme of monitoring, review and improvement to procedures and data handling.
  • Have a Data Protection Officer.
24
Q

What are the penalties?

A

Maximum fine of £17.5 million or 4% of annual global turnover.

25
Q

Principles of the Bribery Act 2010?

A

PCRCDM

  • Proportionality
  • Commitment (Top Level)
  • Risk Assessment
  • Communication
  • Due Diligence
  • Monitor and Review.
26
Q

What are the types of breaches?

A
  • Disclosure
  • Destruction
  • Alteration
27
Q

Who is accountable for data breaches?

A

If not suitable training and security in place then CEO/directors.

If other situation, then Data Protection Officer.

If sole trader, then the individual.

Individuals in a firm can be fined if they destroy evidence of the data breach or seek to access data without permission to do so.

28
Q

What are the principles of GDPR?

A

Lawfulness, Fairness and Transparency
Purpose limitation
Data minimisation
Accuracy
Storage Limitation
Integrity and Confidentiality
Accountability