Data Protection Act Flashcards
years
1988 and 2003
anyone has the right to find out
if an organisation holds data about them
to ask for a copy of this data
role of data protection commissioner
aims to ensure that individuals rights are being upheld and that the data controllers respect data protection regulation
personal data
any information that can identify an individual person
includes: name, ID, address, phone number
anything relating to the identity of a person
requires organisations to
- collect no more data than is necessary from an individual for its intended purpose
- obtain data fairly by giving notice and reason for collection
- retain the data for no longer than is necessary and only for that purpose
- keep data safe and secure
- provide an individual with a copy of their data if requested
GDPR
general data protection regulation
individuals have the right to
- obtain details about how their data is being processed
- obtain copies of their data
- have incorrect or incomplete data corrected
- have their data erased if it holds no purpose
fines
DPC can now fine up to €20 mil or 4% of global turnover for serious infringements
permits individuals to seek compensation for breaches of their data rights, even in cases where no financial or material damage was done