DPA_04-PRINCIPLES AND OBLIGATIONS OF PERSONAL DATA PROTECTION Flashcards

1
Q

What is the principle of lawful processing of personal data?

A

Personal data must be processed lawfully, fairly, and transparently.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What does the principle of purpose limitation entail?

A

Personal data should be collected for
1. explicit,
2. specified, and
3. legitimate purposes
and not further processed in a manner incompatible with those purposes.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is meant by data minimization?

A

Personal data collected should be
1. adequate,
2. relevant, and
3. limited
to what is necessary for the purposes for which it is processed.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

How should personal data be maintained according to the accuracy principle?

A

Personal data must be
1. accurate and
2. kept up to date
, with steps taken to rectify inaccuracies without delay.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is the Storage (retention) limitation principle?

A

Personal data should not be kept in a form that identifies data subjects for longer than necessary for the purposes for which it was collected.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What does the principle of security require?

A

Data controllers and processors must
1. implement appropriate technical and
2. organizational measures
to protect personal data against unauthorized access or processing.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is the significance of the right to privacy in data protection?

A

Personal data must be processed in accordance with the right to privacy of the data subject.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is required for the transfer of personal data outside Kenya?

A

Personal data may not be transferred outside Kenya unless there are
1. adequate data protection safeguards or
2. consent
from the data subject.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is the duty to notify in the context of data protection?

A

Data controllers must notify data subjects about the collection and processing of their personal data.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is a data protection impact assessment?

A

It is an assessment to evaluate the impact of processing operations on the protection of personal data.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What are the conditions for obtaining consent from data subjects?

A

Consent must be
1. freely given,
2. specific,
3. informed
, and
4. unambiguous.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is the principle of data protection by design?

A

Data protection measures should be integrated into the development of business processes and systems from the outset.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What does the principle of data protection by default entail?

A

Only personal data necessary for each specific purpose of processing should be processed by default.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What rights do data subjects have under the data protection principles?

A

Data subjects have rights such as access, rectification, erasure, and data portability.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is the obligation of data controllers regarding data breaches?

A

They must notify the Data Protection Commissioner and affected data subjects of any data breaches.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is the role of the Data Protection Commissioner in enforcing these principles?

A

The Commissioner
oversees compliance,
conducts audits, and
can impose penalties for violations.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

What is the significance of transparency in data processing?

A

Data subjects must be informed about how their personal data is being used, enhancing trust and accountability.

18
Q

What is the principle of accountability in data protection?

A

Data controllers and processors are responsible for complying with data protection laws and must demonstrate compliance.

19
Q

What is the importance of organizational measures in data protection?

A

They ensure that data protection principles are implemented effectively within an organization.

20
Q

What is the principle of restriction on processing?

A

Personal data should not be processed in a way that is incompatible with the purposes for which it was collected.

21
Q

What is the right to object in data protection?

A

Data subjects have the right to object to the processing of their personal data under certain conditions.

22
Q

What is the principle of fairness in data processing?

A

Personal data must be processed in a manner that is fair to the data subject, avoiding any negative impact on their rights.

23
Q

What does the principle of transparency require from data controllers?

A

Data controllers must provide clear and accessible information to data subjects about how their data is processed.

24
Q

What is the significance of explicit consent in data processing?

A

Explicit consent is required for processing sensitive personal data, ensuring that data subjects are fully aware of the implications.

25
How should data controllers handle inaccurate personal data?
They must take every reasonable step to ensure that inaccurate personal data is erased or rectified without delay.
26
What is the principle of data portability?
Data subjects have the right to receive their personal data in a structured, commonly used, and machine-readable format and to transmit it to another controller.
27
What does the principle of integrity and confidentiality entail?
Personal data must be processed securely to protect against unauthorized access, loss, or damage.
28
What is the role of data protection training for employees?
Employees must be trained on data protection principles to ensure compliance and safeguard personal data.
29
What is the requirement for conducting a data protection impact assessment (DPIA)?
A DPIA is required when processing is likely to result in a high risk to the rights and freedoms of data subjects.
30
What does the principle of accountability entail for data processors?
Data processors must demonstrate compliance with data protection laws and be able to show evidence of their practices.
31
What is the obligation of data controllers regarding data subject rights?
Data controllers must facilitate the exercise of data subject rights, such as access and rectification.
32
What is the significance of documenting processing activities?
Documenting processing activities helps demonstrate compliance and accountability under data protection laws.
33
What is the principle of purpose limitation in data collection?
Data should only be collected for specific, legitimate purposes and not used for unrelated purposes.
34
How does the principle of necessity apply to data processing?
Personal data should only be processed if it is necessary for the intended purpose, avoiding excessive data collection.
35
What is the requirement for data breach notifications?
Data controllers must notify the Data Protection Commissioner and affected individuals without undue delay after becoming aware of a breach.
36
What is the principle of non-discrimination in data processing?
Data subjects should not be discriminated against based on their personal data, ensuring equal treatment.
37
What does the principle of data retention specify?
Personal data should be retained only for as long as necessary to fulfill the purposes for which it was collected.
38
What is the role of third-party processors in data protection?
Third-party processors must comply with data protection principles and ensure adequate safeguards are in place.
39
What is the significance of privacy notices for data subjects?
Privacy notices inform data subjects about their rights and how their data will be used, promoting transparency.
40
What is the principle of risk assessment in data processing?
Data controllers must assess risks associated with data processing activities to implement appropriate safeguards.
41
What is the requirement for consent withdrawal?
Data subjects have the right to withdraw their consent at any time, and this must be made easy and accessible.
42
What is the importance of regular audits in data protection?
Regular audits help ensure ongoing compliance with data protection laws and identify areas for improvement.