Data Protection Flashcards
When did the Data Protection Act 2018 come into force?
May 2018
What are the principles detailed in the Data Protection Act 2018?
Lawfulness, Fairness and Transparency
Purpose Limitation
Data Minimisation
Accountability
What is meant by Data Minimisation?
Personal data that is collected by an organisation should be only what is necessary for the specific purpose.
What is meant by Purpose Limitation?
Personal data should be used only for the explicit purpose for which it was given.
What has been nominated by the UK to regulate and enforce GDPR?
The Information Commissioner’s Office (ICO)
What is the maximum fine which can be imposed for breaches in data protection in the EU?
The greater of €20 million, or 4% of the organisation’s annual global turnover.
Can the EU fine apply to UK businesses if they process personal data of EU residents?
Yes
What is the maximum fine which can be imposed for breaches in data protection in the UK? *
*Processing UK residents’ personal data
The greater of £17.5 million, or 4% of the organisation’s annual global turnover.
How long, after a personal data breach is discovered, must an organisation report it to the relevant supervisory body?
72 hours.
What must organisations ensure they have, to ensure data protection?
Robust data breach detection, investigation and internal reporting procedures in place.
They must keep a record of any personal data breaches.