Data Protection Flashcards
1
Q
What are the principles of the Data Protection Act 1998?
A
- lawfully processed for relevant purpose
- Processed only for relevant purposes
- necessary and not excessive to hold
- up to date
- Not kept longer than necessary
- Processed in line with the data subject rights
- Kept securely
- Not transferred to countries with different data protection laws.
2
Q
Who polices the DPA 1998? And what is the penalty?
A
Information Commissions Office (ICO)
Penalty is a fine - £500k max
3
Q
What is your company doing about GDPR?
A
TBC
4
Q
When does GDPR come into force?
A
25 May 2018 (next Friday)
5
Q
What are the key requirements of GDPR?
A
- Conduct data protection impact assessment
- Rights for individuals to have access to information held and to have it erased.
- data accountability - organisations have to prove how they are complying with the new regulations.
- Security breaches will need to be reported to ICO
- Max fine of €20m or 4% global turn over