From Book Flashcards

1
Q

What are the 3 operational objectives of the FCA?

A
  1. Secure an appropriate degree of protection for insurers
  2. Protect and enhance the integrity of the UK financial system
  3. Promote effective competition in the interests of consumers in the markets for regulated financial services and services provided by recognised investment exchanges on certain regulated activities.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

From April 2014 the FCA took over some activities from the Office of fair trading including…?

A
  • Lending or brokering credit, whether or not secured on land;
  • Being a credit reference agency or providing credit information services
  • Debt collection and debt administration services; and
  • Carrying out activities in relation to contracts for the hire of goods.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

In terms of FCA, PRA, PRC and FPC who has power over whom?

A

FPC / PRC both committees in the bank of England

FPC has formal powers of direction over the PRA and the FCA where such powers have been granted by HM treasury

PRC - powers over PRA

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

List the regulated activities under the Regulated Activities Order 2001

A

AEIO MAD

Accepting Deposits
Effecting or carrying out contracts of insurance as principle
Issuing electronic money
OTFs

MTFs
Arranging a mortgage or other home finance transaction
Dealing in, arranging deals in or managing investments

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

what does the information commissioners office oversee?

A
  • The data protection act
  • The general data protection regulation (GDPR)
  • The freedom of information act
  • The environmental information regulations
  • The privacy and electronic communications regulations
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Who must data processors notify before carrying out any data processing?

A

The relevant national authority

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What must data protection comply with?

A

European data protection principles e.g. processing data fairly and lawfully, and using data for specific and legitimate purposes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What will firms outside the EU have to do if they want to target customers inside of the EU ?

A

Meet GDPR

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

A data controller must provide certain information to individuals about whom they hold personal data what is this?

A

Data controller must disclose their identity, details of the data they hold and what they plan to do with it

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

what measures must be put in place in reference to GDPR?

A

Technical and organisational measures to protect personal data against accidental loss/ destruction, unauthorised access or other unlawful processing.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

In terms of GDPR what written agreements must be made and entered into by whom?

A

Enter into written agreements to ensure that data processors act only on the data controller’s instructions and comply with the same security obligations that are imposed on data controllers under the applicable national legislation.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Under GDPR what measures must data processors put iin place?

A
  • Implement technical and organisational security measures
  • Protect personal data
  • Keep a register of data processing activities
  • Comply with the rules relating to the transfer of personal data outside of the EU
  • Comply to restrictions on their ability to engage sub-processors
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What must consent around GDPR be?

A

Specific

Customer silence or inactivity to tick boxes is no longer sufficient

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

When consent is gained for GDPR what is it valid for?

A

Valid only for the stated purpose for which it was collected and not for any other purpose.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Once consent is given what does the data subject have the right to do?

A

Withdraw the consent at any time

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is a fair processing notice?

A

Info organisations are required to give data subjects:

  • grounds of data
  • period of retention
  • mechanism of export (if exported outside of the EU)
  • source of the data

must also give their rights/ right to complain/ right to withdraw data

17
Q

What is data subject rights?

A
  • right to have data transmitted to themselves or another data controller
  • to require controller to erase the data in some circumstances
  • right to request more info on processing through a subject access request
18
Q

If a data participant requests information on data/ uses their rights how long do organisations have to respond?

A

Within one month

19
Q

Can data controllers charge a fee for data requests?

A

Generally no

20
Q

if there is a data breach whom must be notified and within what timeframe?

A

ICO within 72 hours

Individuals to whom the personal data relates without undue delay.

21
Q

What must organisations maintain in terms of a data breach?

A

A data breach register

22
Q

When can data be exported outside the EEA?

A

Only when the recipient non-EEA country is either deemed by the European Commission to offer adequate data protection safeguards, or a valid export mechansim has been put in place

23
Q

If data is breached what can fines be? - certain important provisions

A

20 million EUROS or 4% of global annual turnover whatever is the greater

24
Q

If data is breached what can fines be? - other provisions

A

10 million EUROS or 2% of global annual turnover whatever is the greater

25
Q

what do the investment provisions of the Trustee act 2000 not apply to?

A

Occupational pension schemes, authorised unit trusts or certain schemes under the charities act 2011