Freedom of info Flashcards
Freedom of Information Act date
2000
What does Freedom of Information do?
Access to information of PUBLIC bodies
Are there exceptions? Name the two.
Yes. Absolute and qualified exceptions.
Protection of Freedoms Act 2012 part 6 did what….
Added new provisions to Freedom of Information:
DATASETS
Name some examples of absolute exemptions?
Confidential information
If the info could already be obtained under the Data Protection Act
Is contained in court records
Name the two types of qualified examples
Class
Harm
How many FOI requests in Q1 2016
12791
What is the most common exemption?
46% about personal information
When was Environment Information Regulations?
2004
What is a publication scheme?
Commitment to make certain information available.
How can information be requested for FOI?
letter or email
How long should information take in FOI?
20 days unless there is delay
Are charges allowed?
Yes. Small.
Which US Amendment protects for some level of privacy?
Fourth
What is the agency responsible for data protection?
Information Commissioners Office
ICO
Data Protection Act date?
1998
What does Data Protect Act (1998) ensure?
that information is used in the way it was originally given
When was Data Protection Act updated and why?
2018
To align with GDPR
What does GDPR stand for?
General Data Protection Regulation
When was GDPR introduced?
25th May 2018
What does GDPR cover?
Personal data
What is personal data?
Information relation to a person who can be identified or who can indirectly identified.
Does company information relate to personal data?
Nope
Give some examples of personal data
Biography
Looks
Where you work
Education
What is a data controller?
Someone who determines the purpose and means of processing data
What is a data processor?
Responsible for processing personal data on behalf of a controller
Does GDPR apply to public and private?
Yes
GDPR: What about in EU/Out of EU for
It’s about EU citizens or if you operate in the EU.
What does GDPR not apply for?
Processing carried out by a person for themselves
National security stuff
Law Enforcement Directive
How is an individual ‘identifiable’?
If they can be distinguished from others
What is GDPR max fine?
€20 million or 4% of company’s worldwide turnover.
What are the seven GDPR principles?
Lawfulness, fairness, transparency Purpose limitation Data minimisation Accuracy Storage limitation Integrity and confidence Accountability
What is point of lawfulness and GDPR?
Assures people don’t do naughty things with data. Must be clear and open about uses.
What is point of purpose limitation and GDPR?
you must be clear from the start what data you’re using.
you can only use it for other things if: compatible, consent, clear legally
What is point of minimisation and GDPR?
data must be adequate
relevant
limited
What is point of accuracy and GDPR?
you must be sure data is accurate
you need to take steps to correct or erase errors
What is point of storage limitation and GDPR?
don’t keep data for too long
What is point of integrity and GDPR?
Security is important
What is point of accountability and GDPR?
you need to prove you are adhering to GDPR
how many things for lawful basis for processing need apply?
at least one
name 6 lawful basis for processing
consent contract legal obligation vital interests public task legit interest
What is point of right to be informed and GDPR?
you have a right to know how your data is being used
What is point of right to access informed and GDPR?
subject access - you can access data held on you. YOU CANNOT BE CHARGED
What is point of right to rectification informed and GDPR?
you can make adjustments to inaccurate info
What is point of right to erasure informed and GDPR?
the right to be forgotton
is the right to erasure absolute?
no
Where does erasure not apply?
legal bits, freedom of expression, public interest
What is point of right to restrict and GDPR?
you can restrict or suppress your data
What is point of right to object and GDPR?
you can object to the way your data is being used
you can stop direct marketing
What is point of right to portability and GDPR?
the right to reuse data across services.
information only applies to information you’ve supplied the controller.
is GDPR all encompassing
no. there can be exemptions made by EU member states