Data Protection Flashcards

1
Q

What is GDPR?

A

A law that dictates how personal data is processed and transferred in the European Union (EU).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are the key principles of GDPR (7)?

A
  • Lawfulness, fairness and transparency.
  • Purpose limitation.
  • Data minimisation.
  • Accuracy.
  • Storage limitation.
  • Integrity and confidentiality (security)
  • Accountability.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Through which piece of legislation are the General Data Protection Regulations (GDPR) implemented?

A

The Data Protection Act 2018.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Can you name 3 of the 8 principles of the Data Protection Act 2018?

A
  • Fairly and lawfully processed: Personal data must be processed fairly and lawfully.
  • Purpose: Personal data must be obtained for one or more specified and lawful purpose.
  • Adequacy: Personal data must be relevant and not excessive.
  • Accuracy: Personal data must be accurate and kept up to date.
  • Storage: Personal data must not be kept longer than is necessary.
  • Rights: Your rights include the right to see any data held on you, and the right to correct inaccurate data.
  • Security: Personal data must be kept secure.
  • International transfers: Personal data must not be transferred to other countries outside the European Economic Area, unless those countries have similar data protection laws.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

How long should a firm hold a client’s data for following completion of an instruction?

A

6 years from when the incident occurred, 12 years for some instructions (projects – 12 deed limitation period).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Who should data breaches be reported to?

A

Manager, data protection officer.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

How does your company securely store data?

A

Cloud storage, encrypted, VPN.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Is there any legislation or legal process your company will follow for data?

A

Data Protection Act 2018.
GDPR.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Can you provide an example of a legal requirement that your company will have to follow regarding data?

A

Someone can request a copy of their data (Subject Access Request).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

How do you verify your data?

A

Use public records e.g. land registry.
Compare against multiple sources to confirm consistency.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

How does your treatment of data comply with current legislation?

A
  • Personal data is kept securely.
  • Client date is kept for 6 years from when the incident occurred, 12 years for some instructions (projects – 12 deed limitation period).
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is meant by Article 5 of GDPR when it says ‘kept in a form that permits identification of data subjects for no longer than is necessary’? How does this relevant to your role?

A
  • You’re not allowed to hold personal information for longer than necessary i.e. contact information.
  • This is relevant becuase this information has to be archived after a certain period of time (6 years or 12 years for some instructions - 12 year deed limitation).
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Why do you think data you hold needs to be accurate?

A

To comply with GDPR [Article 5] - states personal data must be accurate otherwise it must be deleted.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What are the consumer rights under GDPR?

A
  • Right to be informed.
  • Right of access.
  • Right to rectification.
  • Right erasure.
  • Right to restriction of processing.
  • Right to data portability.
  • Right to object.
  • Rights related to automated decision-making and profiling.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is the definition of personal data?

A

Any information relating to an identifiable person.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What would constitute a security breach? What is your company policy on reporting a breach? How long do you have to report it to ICO (Information Commissioner’s Office)?

A
  • Losing confidential files, stolen laptop.
  • Notify the affected parties and describe the impact.
  • Must notify the ICO within 72 hours of becoming aware of breach.
17
Q

How long should you keep deeds on file?

A

Minimum of 15 years.
[Claim of negligence can be made up to 15 years after the negligent act occurred].