Data protection concepts Flashcards

1
Q

4 building blocks of the term “Personal data” are:

A
  • Any information
  • Relating to
  • An identified or identifiable
  • Natural person
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are the aspects of term “information”?

A
  • Nature (objective/subjective)
  • Content (any sort of information)
  • Format (any form)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are the elements of term “relating to”?

A
  • Content (information is about person)
  • Purpose (to evaluate/consider/analyze)
  • result (impact on rights/interests)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Sensitive personal data is data about:

A
  • racial or ethnic
  • political
  • religious/philosophical
  • trade union membership
  • genetic data
  • biometric for purpose uniq identifying
  • regarding health
  • sex life/orientation
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are the 5 building blocks of concept Controller

A
  1. Natural or legal person, public authority, agency or other body
  2. Determines
  3. Alone or jointly with others
  4. The purpose and means
  5. of the processing of PD
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Example when Controller has no contact with PD but still remains controller

A

Ordering Marketing research with specific parameters.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Converging decision as per Guidelines is

A

Decision of joint controllers, which complement each other, necessary for processing and have tangible impact on determination of purpose and means

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Case example of joint controllership

A

Fashion ID + Facebook like button

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What are the 2 building blocks of concept Data processor

A
  1. Separate legal entity from Controller
  2. Processes PD on behalf of Controller
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Example when entity can be processor and controller simultaneously

A

Pay role provider processes PD to administer benefits, but it also can use same data of key management for procurement purposes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Which GDPR article sets the requirement for processing agreement?

A

28

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

requirements as per art 28 for processing agreement:

A
  1. processing only on instructions
  2. persons processing data are bound with confidentiality
  3. Take all security measures as per art. 32
  4. Assist Controller to execute data subject rights
  5. Assist Controller to comply with security, DPIA, breach notif.
    Art.32-36
  6. At Controller`s choice delete o return PD
  7. Help Controller to demonstrate compliance w Art 28 (audit, insp)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What are the building blocks of concept Processing?

A
  1. Any operation or sets of operations
  2. performed on PD or sets of PD
    such as:
    - Collection
    - recording
    - organization
    - structuring
    - storage
    - adaptation
    - retrieval
    - consultation
    - use
    - disclosure
    - alignment
    - erasure
    - destruction
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

As per territorial scope, GDPR applies to:

A
  • EU-established organizations (in context of their activity)
    -organization offer to sell products - services / or monitor individuals in EU
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

name guidelines detailing territorial scope

A

EDPB Guidelines 3/2018

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

EU-established organizations means

A
  • company established in EU, doesn`t matter if processing within EU
  • establishment = effective and real exercise of activity
  • effective = bank account, representative, redirecting on EU web sites
17
Q

GDPR applies to non-EU established companies when

A

processing data of data subjects who are in EU
- offering goods and services
-monitoring behavior in EU
-

18
Q

exclusions when GDPR does not apply to non-EU established:

A

Company targets of goods and services on person in EU inadvertently or incidentally

19
Q

113

A