From Book Flashcards
What are the 3 operational objectives of the FCA?
- Secure an appropriate degree of protection for insurers
- Protect and enhance the integrity of the UK financial system
- Promote effective competition in the interests of consumers in the markets for regulated financial services and services provided by recognised investment exchanges on certain regulated activities.
From April 2014 the FCA took over some activities from the Office of fair trading including…?
- Lending or brokering credit, whether or not secured on land;
- Being a credit reference agency or providing credit information services
- Debt collection and debt administration services; and
- Carrying out activities in relation to contracts for the hire of goods.
In terms of FCA, PRA, PRC and FPC who has power over whom?
FPC / PRC both committees in the bank of England
FPC has formal powers of direction over the PRA and the FCA where such powers have been granted by HM treasury
PRC - powers over PRA
List the regulated activities under the Regulated Activities Order 2001
AEIO MAD
Accepting Deposits
Effecting or carrying out contracts of insurance as principle
Issuing electronic money
OTFs
MTFs
Arranging a mortgage or other home finance transaction
Dealing in, arranging deals in or managing investments
what does the information commissioners office oversee?
- The data protection act
- The general data protection regulation (GDPR)
- The freedom of information act
- The environmental information regulations
- The privacy and electronic communications regulations
Who must data processors notify before carrying out any data processing?
The relevant national authority
What must data protection comply with?
European data protection principles e.g. processing data fairly and lawfully, and using data for specific and legitimate purposes
What will firms outside the EU have to do if they want to target customers inside of the EU ?
Meet GDPR
A data controller must provide certain information to individuals about whom they hold personal data what is this?
Data controller must disclose their identity, details of the data they hold and what they plan to do with it
what measures must be put in place in reference to GDPR?
Technical and organisational measures to protect personal data against accidental loss/ destruction, unauthorised access or other unlawful processing.
In terms of GDPR what written agreements must be made and entered into by whom?
Enter into written agreements to ensure that data processors act only on the data controller’s instructions and comply with the same security obligations that are imposed on data controllers under the applicable national legislation.
Under GDPR what measures must data processors put iin place?
- Implement technical and organisational security measures
- Protect personal data
- Keep a register of data processing activities
- Comply with the rules relating to the transfer of personal data outside of the EU
- Comply to restrictions on their ability to engage sub-processors
What must consent around GDPR be?
Specific
Customer silence or inactivity to tick boxes is no longer sufficient
When consent is gained for GDPR what is it valid for?
Valid only for the stated purpose for which it was collected and not for any other purpose.
Once consent is given what does the data subject have the right to do?
Withdraw the consent at any time