DPA_04-PRINCIPLES AND OBLIGATIONS OF PERSONAL DATA PROTECTION Flashcards
What is the principle of lawful processing of personal data?
Personal data must be processed lawfully, fairly, and transparently.
What does the principle of purpose limitation entail?
Personal data should be collected for
1. explicit,
2. specified, and
3. legitimate purposes and not further processed in a manner incompatible with those purposes.
What is meant by data minimization?
Personal data collected should be
1. adequate,
2. relevant, and
3. limited to what is necessary for the purposes for which it is processed.
How should personal data be maintained according to the accuracy principle?
Personal data must be
1. accurate and
2. kept up to date, with steps taken to rectify inaccuracies without delay.
What is the Storage (retention) limitation principle?
Personal data should not be kept in a form that identifies data subjects for longer than necessary for the purposes for which it was collected.
What does the principle of security require?
Data controllers and processors must
1. implement appropriate technical and
2. organizational measures to protect personal data against unauthorized access or processing.
What is the significance of the right to privacy in data protection?
Personal data must be processed in accordance with the right to privacy of the data subject.
What is required for the transfer of personal data outside Kenya?
Personal data may not be transferred outside Kenya unless there are
1. adequate data protection safeguards or
2. consent from the data subject.
What is the duty to notify in the context of data protection?
Data controllers must notify data subjects about the collection and processing of their personal data.
What is a data protection impact assessment?
It is an assessment to evaluate the impact of processing operations on the protection of personal data.
What are the conditions for obtaining consent from data subjects?
Consent must be
1. freely given,
2. specific,
3. informed, and
4. unambiguous.
What is the principle of data protection by design?
Data protection measures should be integrated into the development of business processes and systems from the outset.
What does the principle of data protection by default entail?
Only personal data necessary for each specific purpose of processing should be processed by default.
What rights do data subjects have under the data protection principles?
Data subjects have rights such as access, rectification, erasure, and data portability.
What is the obligation of data controllers regarding data breaches?
They must notify the Data Protection Commissioner and affected data subjects of any data breaches.
What is the role of the Data Protection Commissioner in enforcing these principles?
The Commissioner
oversees compliance,
conducts audits, and
can impose penalties for violations.
What is the significance of transparency in data processing?
Data subjects must be informed about how their personal data is being used, enhancing trust and accountability.
What is the principle of accountability in data protection?
Data controllers and processors are responsible for complying with data protection laws and must demonstrate compliance.
What is the importance of organizational measures in data protection?
They ensure that data protection principles are implemented effectively within an organization.
What is the principle of restriction on processing?
Personal data should not be processed in a way that is incompatible with the purposes for which it was collected.
What is the right to object in data protection?
Data subjects have the right to object to the processing of their personal data under certain conditions.
What is the principle of fairness in data processing?
Personal data must be processed in a manner that is fair to the data subject, avoiding any negative impact on their rights.
What does the principle of transparency require from data controllers?
Data controllers must provide clear and accessible information to data subjects about how their data is processed.
What is the significance of explicit consent in data processing?
Explicit consent is required for processing sensitive personal data, ensuring that data subjects are fully aware of the implications.