Data Protection Flashcards

1
Q

What is DPA

A

Data Protection act 1998

Deigned to implement EU data protection directive

Protects the rights and freedoms of individuals in the processing of personal data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is Personal Data ?

A

Info that relates to a living individual (data subject) which identifies that person from the data

*Data is valuable

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are data controllers?

A

Organisations that process personal data

DPA is applicable whenever data controller processes personal and/ or sensitive personal data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What does ‘processing’ involve?

A

Obtaining, storing & retrieving data by computer or recording in a structured manual filing system

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Give examples of personal data and sensitive personal data

A

Personal Data

  • Name
  • DOB
  • Address

*info is easily accessible as the client must opt in (i.e terms and conditions)

Sensitive Personal Data

  • Ethic origin
  • Political Opinions/ Religious Beliefs
  • Criminal offences/ alleged
  • Sexuality
  • Physical/ mental Health
  • Member of the trade union
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What are the conditions of the DPA to process data?

A
  • Under DPA organisations processing data must notify the relevant authority (info commissioner) of the purpose & manner which they process the data
  • Info is recorded in a register which can be inspected by the public
  • Conditions to process sensitive personal data include:
  • obtain explicit consent from the individual
  • must be required by law to process the data (I.e employment purposes)
  • processing must occur to protect the vital interests of the data subject
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What are the 8 Principles of the DPA

A

1) Rights of the individual (under the Act)
2) Personal data shall not be transferred to unsecured country outside European Economic Area / unless it ensures it offers the same adequate level of protection & security
3) Length of time keeping the processed data is no longer than necessary for its purpose
4) Secure Environmental Protection Systems (I.e. Fire walls, shred bins, clear desk, controls)
5) Personal Data only obtained for specified/ registered purpose / not incompatible with those purposes
6) Personal Data shall be accurate & up to date
7) Personal Data processed fairly and lawfully
8) Personal Data s adequate, relevant & not excessive in relation to the purpose for which it’s processed
* appropriate measures taken against unauthorised or unlawful processing of personal data & against accidental loss, damage or destruction of data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

State the criteria that must be met for data controllers in relation to;

1) data obtained fairly and lawfully
2) data processed in accordance with individuals rights
3) secure environmental systems p

A

1) -individual given consent / suitable system of opt in or out clauses
- purpose to monitor equal opportunities
- process necessary for contract

2) -privacy
- access personal data (£10)
- right to object to direct marketing
- right to issue data subject notice to stop processing if believed causing damage or distress
- right to compensation if suffered damage
- right to rectify, cease or destroy data

3)if dealing with 3rd party must have written consent and ensure data processor only acts on his instructions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What are the offences of DPA

A
  • processing personal data without notification
  • failure to notify the information commissioner
  • making a false statement in response to an information notice
  • obstructing warrant holder
  • unlawfully obtaining/ selling personal data
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Penalties for Non-compliance with the DPA

A

-offences are criminal however don’t carry prison sentences

Convictions

  • Magistrates Court = £5000 fine
  • Crown Court = unlimited fines
  • if info commissioner believes data controller hasn’t complied with the DPA principles it can issue enforcement notice to stop processing or comply with the principles
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

DPA offshore

A

Many offshore centres legislation is similar to the DPA / highly relevant as service providers may be considered as data controllers in their jurisdiction

GSY & JSY consider creation of single data protection commissioner responsible for both islands / example of crown dependencies cooperating to provide more consistent approach to those dealing and benefit organisations operating in both

This is important as DPA requirements often overlap & conflict with other legislation already in force

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Data Protection Law in Jersey

A

Contained in Data Protection (jersey) law 2005

Regulator, data protection commissioner, law office department and joint financial crime unit = FIU published guidance for business in response to concerns of interaction in JSY AML and data protection legislation

Concerns;

  • obligation not to tip off about SAR made
  • Individuals rights to access data
  • guidance concluded while exemptions from subject access provision never assume they apply to SAR of disclosure of personal data would lead to tipping off offence under AML
  • when subject access requested business must carefully consider disclosure of info in SAR would prejudice prevention of detection of crime, impact regulation of financial services, lead to tipping off offence

FIU (financial intelligence unit) - authority of jurisdiction responsible for receiving and dealing with SAR from institution

How well did you know this?
1
Not at all
2
3
4
5
Perfectly