Data Protection Law Flashcards
Who are the parties involved in data protection?
Data controller - decider
Data processor - doer
Personal subject - us
When does the Data Protection Act apply?
When personal data is held on computer or manual files by any organisation
What is included in personal data?
Any information including recording of facts and expression of opinion about the individual
Who is the Information Commissioner?
UK regulator for data protection
Statutory power to enforce compliance
Must be informed within 72 hours of a breach
What are the repercussions for non-compliance?
Criminal conviction
Fine up to £18 million or 4% of global turnover
What are the data protection principles?
Lawfulness, fairness and transparency - valid grounds for holding data
Purpose limitation - recorded and made clear to data subject from start
Data minimisation - adequate, relevant and not excessive
Accurate - not incorrect
Storage limitation - not kept longer than necessary
Integrity and confidentiality - appropriate security measures
What are the rights of the data subject?
Informed - purpose and retention policy
Access - request info verbally/written provided in 1 month
Rectification - inaccurate info rectified
Erasure - have information erased
Data portability - obtain data to use in different service
Object
Automated decision making and profiling
What are the exemptions from the Act?
Employment law
Academic institutions
Scientific/historical research organisations
Individual rights limited where used to commit crimes, disrupt legal proceedings/public authorities and regulators