GDPR Flashcards

1
Q

What is Personal data?

A

Any information about 1 or more persons relating to a person can be identified, directly or indirectly, such as name, identification number, location data. Online identifiers including IP address and and cookies are personal data as well

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are controllers and processors?

A

data controllers - determines the purpose for which and the manner in which the data is processed

Data processors - Managers of all, they process the data on behalf of the data controller

The regulation seperates responsibilites and duties of data controllers and processors

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are fines and enforcement and enforcement regime

A

Penalties equal to the greater of 10 million euro or 2% of the entitys global gross revenue for violations of record keeping, security, breach notification, and privacy impact assessment obligations

Violations of obligations related to legal justfiication for processing the data rights and cross border data is greater than 20 million euro or 4% of the entity global revenue

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is the Data protection officer?

A

Is a mandatory role for all companies that collect or process EU citizens person data, under Article 37 of GDPR. responsible for education the companys about compliance and conduct regular security audits.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is privacy managment?

A

The is where the appropriate orgaizational controls must be developed according to the degree of risk associated with the processing acitivites.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is consent?

A

any freely given, specific, informed and unambigous indication of his or her wishes

Consent should be demonstrable
Consent must be given freely given
Withdra of consent should always be able to take away

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What about breach and notification guidlines?

A

A exposure of personal data and unauthorized use of data and should be notified no less than 72 hours after breach and if not it should given a justification for delay the controller has this responsibility

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is DSAR?

A

Individuals have more information on how their data is be used and must be executed without undue delay and at the latest with in one month

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is the right to be forgetten?

A

Controllers must inform subjects of the period of time data will be retained and the client has the right for the data to be cleared for the data centers.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly