DATA PROTECTION Flashcards

1
Q

DATA CONTROLLER

A

Determine purposes and means of processing data.

Ensure compliance with data protection legislation.
Obtain consent, provide transparency, and implement security measures.

Respect data subjects’ rights regarding their personal data.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

DATA PROCESSOR

A

Anyone who process personal data on behalf of data controller and is not an employee of the data controller, for example online hotel booking services.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Personal data

A

data related to living person who can be identified from data the data controller likely have. It includes expression of opinion of the person and indicates the intention of the data controller tozards the individual.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

DATA SUBJECT

A

The individual who is the subject of the personal data.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

PROCESSING

A

means obtaining, recording or holding information or data or carrying out any operation on it.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Discuss how UK Data Protection legislation applies to cookies used in website.

A

*Consent: Obtain informed and explicit consent for non-essential cookies.

*Transparency: Provide clear information about cookie types, purposes, and third-party involvement.

*Data Protection Principles: Adhere to principles like lawfulness, fairness, and accuracy in processing cookie data.

*Rights of Data Subjects: Users have rights to access, rectify, and request erasure of their cookie data.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

why UK Data Protection legislation means that technical and organisational
measures are needed for the security of website

A

Encryption: Implement encryption protocols for data transmission.

Access Controls: Restrict access to personal data through strong authentication and role-based access.

Data Minimization: Collect and process only necessary personal data to reduce risk.

Regular Audits: Conduct security audits to identify and address vulnerabilities.

Incident Response Plan: Develop a plan to respond effectively to security breaches.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

8 Data protection principles

A

■ Data processing should be legal, fair, and transparent to the individual.

■ Data should only be collected for specified, explicit, and legitimate purposes.

■Only collect and process the data that is necessary for the intended purpose.

■Ensure that the data is accurate and kept up to date.

■Data should not be kept for longer than necessary.

■Data should be kept secure and protected against unauthorized access or processing.

■Be responsible for complying with data protection regulations and demonstrate compliance.

■Respect the rights of individuals regarding their personal data, including the right to access, rectify, erase, and restrict processing.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly