GDPR Flashcards
What is Personal data?
Any information about 1 or more persons relating to a person can be identified, directly or indirectly, such as name, identification number, location data. Online identifiers including IP address and and cookies are personal data as well
What are controllers and processors?
data controllers - determines the purpose for which and the manner in which the data is processed
Data processors - Managers of all, they process the data on behalf of the data controller
The regulation seperates responsibilites and duties of data controllers and processors
What are fines and enforcement and enforcement regime
Penalties equal to the greater of 10 million euro or 2% of the entitys global gross revenue for violations of record keeping, security, breach notification, and privacy impact assessment obligations
Violations of obligations related to legal justfiication for processing the data rights and cross border data is greater than 20 million euro or 4% of the entity global revenue
What is the Data protection officer?
Is a mandatory role for all companies that collect or process EU citizens person data, under Article 37 of GDPR. responsible for education the companys about compliance and conduct regular security audits.
What is privacy managment?
The is where the appropriate orgaizational controls must be developed according to the degree of risk associated with the processing acitivites.
What is consent?
any freely given, specific, informed and unambigous indication of his or her wishes
Consent should be demonstrable
Consent must be given freely given
Withdra of consent should always be able to take away
What about breach and notification guidlines?
A exposure of personal data and unauthorized use of data and should be notified no less than 72 hours after breach and if not it should given a justification for delay the controller has this responsibility
What is DSAR?
Individuals have more information on how their data is be used and must be executed without undue delay and at the latest with in one month
What is the right to be forgetten?
Controllers must inform subjects of the period of time data will be retained and the client has the right for the data to be cleared for the data centers.