DATA PROTECTION Flashcards
DATA CONTROLLER
Determine purposes and means of processing data.
Ensure compliance with data protection legislation.
Obtain consent, provide transparency, and implement security measures.
Respect data subjects’ rights regarding their personal data.
DATA PROCESSOR
Anyone who process personal data on behalf of data controller and is not an employee of the data controller, for example online hotel booking services.
Personal data
data related to living person who can be identified from data the data controller likely have. It includes expression of opinion of the person and indicates the intention of the data controller tozards the individual.
DATA SUBJECT
The individual who is the subject of the personal data.
PROCESSING
means obtaining, recording or holding information or data or carrying out any operation on it.
Discuss how UK Data Protection legislation applies to cookies used in website.
*Consent: Obtain informed and explicit consent for non-essential cookies.
*Transparency: Provide clear information about cookie types, purposes, and third-party involvement.
*Data Protection Principles: Adhere to principles like lawfulness, fairness, and accuracy in processing cookie data.
*Rights of Data Subjects: Users have rights to access, rectify, and request erasure of their cookie data.
why UK Data Protection legislation means that technical and organisational
measures are needed for the security of website
Encryption: Implement encryption protocols for data transmission.
Access Controls: Restrict access to personal data through strong authentication and role-based access.
Data Minimization: Collect and process only necessary personal data to reduce risk.
Regular Audits: Conduct security audits to identify and address vulnerabilities.
Incident Response Plan: Develop a plan to respond effectively to security breaches.
8 Data protection principles
■ Data processing should be legal, fair, and transparent to the individual.
■ Data should only be collected for specified, explicit, and legitimate purposes.
■Only collect and process the data that is necessary for the intended purpose.
■Ensure that the data is accurate and kept up to date.
■Data should not be kept for longer than necessary.
■Data should be kept secure and protected against unauthorized access or processing.
■Be responsible for complying with data protection regulations and demonstrate compliance.
■Respect the rights of individuals regarding their personal data, including the right to access, rectify, erase, and restrict processing.