Data Protection and compliance Flashcards
What is the 2018 Data protection act?
UK legislation controls how your personal information is used by organisations, businesses or the government. That ensures the information is:
Used fairly, lawfully and transparently
Used for specified, explicit purposes
What is personal data?
Information related to an identified or identifiable living human being e.g Bank details and IP address.
What is Sensitive Personal Data?
Distinct personal information that is more sensitive than personal data e.g Racial or ethic origin and Trade union membership.
How should data be used?
- Obtain and process information fairly
- keep it only for one or more specified, explicit purposes
- Use and disclose it only in ways compatible with these purposes
- Keep it safe and secure
- keep it accurate, complete and up-to-date
- Ensure that it is adequate, relevant and not excessive
- Retain for no longer than is necessary
- Give a copy of their personal to an individual, on request.
What is the penalties for non compliance in the UK and EU?
UK GDPR and DPA 2018 set a maximum fine of £17.5 million or 4% of annual global turnover whichever is greater.
The EU set a maximum of €20 million or 4% of annual global turnover whichever is greater.
Who is the governing body for the uphold of information rights?
Information commissioners office