DPA_04-PRINCIPLES AND OBLIGATIONS OF PERSONAL DATA PROTECTION Flashcards
What is the principle of lawful processing of personal data?
Personal data must be processed lawfully, fairly, and transparently.
What does the principle of purpose limitation entail?
Personal data should be collected for
1. explicit,
2. specified, and
3. legitimate purposes and not further processed in a manner incompatible with those purposes.
What is meant by data minimization?
Personal data collected should be
1. adequate,
2. relevant, and
3. limited to what is necessary for the purposes for which it is processed.
How should personal data be maintained according to the accuracy principle?
Personal data must be
1. accurate and
2. kept up to date, with steps taken to rectify inaccuracies without delay.
What is the Storage (retention) limitation principle?
Personal data should not be kept in a form that identifies data subjects for longer than necessary for the purposes for which it was collected.
What does the principle of security require?
Data controllers and processors must
1. implement appropriate technical and
2. organizational measures to protect personal data against unauthorized access or processing.
What is the significance of the right to privacy in data protection?
Personal data must be processed in accordance with the right to privacy of the data subject.
What is required for the transfer of personal data outside Kenya?
Personal data may not be transferred outside Kenya unless there are
1. adequate data protection safeguards or
2. consent from the data subject.
What is the duty to notify in the context of data protection?
Data controllers must notify data subjects about the collection and processing of their personal data.
What is a data protection impact assessment?
It is an assessment to evaluate the impact of processing operations on the protection of personal data.
What are the conditions for obtaining consent from data subjects?
Consent must be
1. freely given,
2. specific,
3. informed, and
4. unambiguous.
What is the principle of data protection by design?
Data protection measures should be integrated into the development of business processes and systems from the outset.
What does the principle of data protection by default entail?
Only personal data necessary for each specific purpose of processing should be processed by default.
What rights do data subjects have under the data protection principles?
Data subjects have rights such as access, rectification, erasure, and data portability.
What is the obligation of data controllers regarding data breaches?
They must notify the Data Protection Commissioner and affected data subjects of any data breaches.
What is the role of the Data Protection Commissioner in enforcing these principles?
The Commissioner
oversees compliance,
conducts audits, and
can impose penalties for violations.