DPA_04-PRINCIPLES AND OBLIGATIONS OF PERSONAL DATA PROTECTION Flashcards

1
Q

What is the principle of lawful processing of personal data?

A

Personal data must be processed lawfully, fairly, and transparently.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What does the principle of purpose limitation entail?

A

Personal data should be collected for
1. explicit,
2. specified, and
3. legitimate purposes
and not further processed in a manner incompatible with those purposes.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is meant by data minimization?

A

Personal data collected should be
1. adequate,
2. relevant, and
3. limited
to what is necessary for the purposes for which it is processed.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

How should personal data be maintained according to the accuracy principle?

A

Personal data must be
1. accurate and
2. kept up to date
, with steps taken to rectify inaccuracies without delay.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is the Storage (retention) limitation principle?

A

Personal data should not be kept in a form that identifies data subjects for longer than necessary for the purposes for which it was collected.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What does the principle of security require?

A

Data controllers and processors must
1. implement appropriate technical and
2. organizational measures
to protect personal data against unauthorized access or processing.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is the significance of the right to privacy in data protection?

A

Personal data must be processed in accordance with the right to privacy of the data subject.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is required for the transfer of personal data outside Kenya?

A

Personal data may not be transferred outside Kenya unless there are
1. adequate data protection safeguards or
2. consent
from the data subject.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is the duty to notify in the context of data protection?

A

Data controllers must notify data subjects about the collection and processing of their personal data.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is a data protection impact assessment?

A

It is an assessment to evaluate the impact of processing operations on the protection of personal data.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What are the conditions for obtaining consent from data subjects?

A

Consent must be
1. freely given,
2. specific,
3. informed
, and
4. unambiguous.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is the principle of data protection by design?

A

Data protection measures should be integrated into the development of business processes and systems from the outset.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What does the principle of data protection by default entail?

A

Only personal data necessary for each specific purpose of processing should be processed by default.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What rights do data subjects have under the data protection principles?

A

Data subjects have rights such as access, rectification, erasure, and data portability.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is the obligation of data controllers regarding data breaches?

A

They must notify the Data Protection Commissioner and affected data subjects of any data breaches.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is the role of the Data Protection Commissioner in enforcing these principles?

A

The Commissioner
oversees compliance,
conducts audits, and
can impose penalties for violations.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

What is the significance of transparency in data processing?

A

Data subjects must be informed about how their personal data is being used, enhancing trust and accountability.

18
Q

What is the principle of accountability in data protection?

A

Data controllers and processors are responsible for complying with data protection laws and must demonstrate compliance.

19
Q

What is the importance of organizational measures in data protection?

A

They ensure that data protection principles are implemented effectively within an organization.

20
Q

What is the principle of restriction on processing?

A

Personal data should not be processed in a way that is incompatible with the purposes for which it was collected.

21
Q

What is the right to object in data protection?

A

Data subjects have the right to object to the processing of their personal data under certain conditions.

22
Q

What is the principle of fairness in data processing?

A

Personal data must be processed in a manner that is fair to the data subject, avoiding any negative impact on their rights.

23
Q

What does the principle of transparency require from data controllers?

A

Data controllers must provide clear and accessible information to data subjects about how their data is processed.

24
Q

What is the significance of explicit consent in data processing?

A

Explicit consent is required for processing sensitive personal data, ensuring that data subjects are fully aware of the implications.

25
Q

How should data controllers handle inaccurate personal data?

A

They must take every reasonable step to ensure that inaccurate personal data is erased or rectified without delay.

26
Q

What is the principle of data portability?

A

Data subjects have the right to receive their personal data in a structured, commonly used, and machine-readable format and to transmit it to another controller.

27
Q

What does the principle of integrity and confidentiality entail?

A

Personal data must be processed securely to protect against unauthorized access, loss, or damage.

28
Q

What is the role of data protection training for employees?

A

Employees must be trained on data protection principles to ensure compliance and safeguard personal data.

29
Q

What is the requirement for conducting a data protection impact assessment (DPIA)?

A

A DPIA is required when processing is likely to result in a high risk to the rights and freedoms of data subjects.

30
Q

What does the principle of accountability entail for data processors?

A

Data processors must demonstrate compliance with data protection laws and be able to show evidence of their practices.

31
Q

What is the obligation of data controllers regarding data subject rights?

A

Data controllers must facilitate the exercise of data subject rights, such as access and rectification.

32
Q

What is the significance of documenting processing activities?

A

Documenting processing activities helps demonstrate compliance and accountability under data protection laws.

33
Q

What is the principle of purpose limitation in data collection?

A

Data should only be collected for specific, legitimate purposes and not used for unrelated purposes.

34
Q

How does the principle of necessity apply to data processing?

A

Personal data should only be processed if it is necessary for the intended purpose, avoiding excessive data collection.

35
Q

What is the requirement for data breach notifications?

A

Data controllers must notify the Data Protection Commissioner and affected individuals without undue delay after becoming aware of a breach.

36
Q

What is the principle of non-discrimination in data processing?

A

Data subjects should not be discriminated against based on their personal data, ensuring equal treatment.

37
Q

What does the principle of data retention specify?

A

Personal data should be retained only for as long as necessary to fulfill the purposes for which it was collected.

38
Q

What is the role of third-party processors in data protection?

A

Third-party processors must comply with data protection principles and ensure adequate safeguards are in place.

39
Q

What is the significance of privacy notices for data subjects?

A

Privacy notices inform data subjects about their rights and how their data will be used, promoting transparency.

40
Q

What is the principle of risk assessment in data processing?

A

Data controllers must assess risks associated with data processing activities to implement appropriate safeguards.

41
Q

What is the requirement for consent withdrawal?

A

Data subjects have the right to withdraw their consent at any time, and this must be made easy and accessible.

42
Q

What is the importance of regular audits in data protection?

A

Regular audits help ensure ongoing compliance with data protection laws and identify areas for improvement.