Data Protection Law & Regulation Flashcards

1
Q

Personal Data

A

Any information relating to an identified or identifiable natural person.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Sensitive Personal Data

A

Subset of personal info; usually requires additional safeguarding of its collection, use, and disclosure

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Pseudonymized Data

A

A unique code or pseudonym is used as a temporary solution to protecting info.

It is reversible.

Subject to EU data protection laws

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Anonymous Data

A

Not related to an identified or an identifiable natural person aka unidentifiable

Not protected by the GDPR

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Data Processing

A

Any operation performed on data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Controller

A

An organization or individual that decides how and why personal data is processed

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Data Processor

A

An organization or individual that processes information on behalf of the data controller

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Data Subject

A

An individual about whom the data is processed

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Territorial Scope

A
  1. Processing of personal data when a controller or processor established in the EU (regardless of whether or not the actual processing takes place in the EU).
  2. Processing the personal data of data subjects in the EU relating to offering goods or services or monitoring behaviour in the EU (where the controller or processor is not established in the EU).
  3. Processing of personal data by a controller not established in the EU but in a place where member state law applies by virtue of public international law.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Material Scope

A

Activities covered by the GDPR

Processing of personal data wholly or partly by automated means

And to the processing of personal data other than by automated means which form part of a filing system

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Exclusions to Material Scope

A

(Processing not regulated by the GDPR)

  1. Activities outside of the scope of EU law: for example national security activities.
  2. Law Enforcement and Public Security
  3. Purely personal or household activities.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Organizations that are not established in the EU that monitor behavior will be subject to the GDPR when:

A

The behavior being monitored occurs within the EU

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

GDPR Processing Principles

Article 5

A
Lawfulness, Fairness and Transparency of Processing
Purpose Limitation
Data Minimization
Accuracy
Storage Limitation
Integrity and Confidentiality
Accountability
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Lawfulness, fairness, and transparency

A

GDPR processing principle:

Data subjects must be aware of the fact that their personal data will be processed, including how the data will be collected, kept and used, so they can make informed decisions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Purpose Limitation

A

Principle that requires collecting and processing personal data for the specified purpose only

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Proportionality

A

considers the amount of data to be collected and whether it is adequate and relevant in relation to the purposes for which it is being processed

17
Q

Accuracy

A

GDPR Principle that states organizations ensure personal data is accurate, complete, and up-to-date

18
Q

Storage limitation (retention)

A

retaining only personal data that is relevant and necessary for the purpose

organizations should retain personal information only as long as necessary to fulfill the stated purpose

19
Q

Integrity and Confidentiality

A

GDPR requires that controllers and processors implement measures to ensure the ongoing confidentiality, integrity, availability and resilience (CIAR) of processing systems and services.

Integrity refers to the consistency, accuracy and trustworthiness of the data

aka security safeguards (OECD)

20
Q

Data Minimization Principle (EU specific)

A

Data controllers must only collect and process personal data that is relevant, necessary and adequate to accomplish the purposes for which it is processed.

Controllers should consider Necessity and Proportionality when applying Data Minimization principle

21
Q

Lawful Processing Criteria

A
  1. Consent
  2. Contract
  3. Legal obligations
  4. Vital interests
  5. Public Interest or official authority
  6. Legitimate interests
22
Q

Consent

A
clearly distinguishable 
intelligible
in clear and plain language
freely given
as easy to withdraw as it was to provide
specific 
informed 
unambiguous
23
Q

Explicit consent

A

Article 9 - special categories

unambiguous, freely given, specific, informed

+ a clear affirmative act by the data subject
(checking opt-in or choosing technical settings for web apps)

24
Q

Contractual necessity

A

Lawful basis for processing

Performance of a contract if the processing is necessary to perform the contract (and data subject is party)
or if the data subject requests the processing to enter into a contract

Ex: Customer purchases book from company, they need process in order to send book