GDPR Flashcards

You may prefer our related Brainscape-certified flashcards:
1
Q

What is REDACTION

A

Redaction is a form of editing. A document can have certain parts “redacted”, meaning
that names and personal details and personal information are removed to ensure
compliance with the requirement to keep a client’s information confidential and secure

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are The GDPR seven key principles?

A
Lawfulness, fairness and transparency
Purpose limitation
Data minimisation
Accuracy
Storage limitation
Integrity and confidentiality (security)
Accountability
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Who does the UK GDPR apply to?

A

The UK GDPR applies to ‘controllers’ and ‘processors’.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

UK GDPR - Define Controller

A

A controller determines the purposes and means of processing personal data.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

UK GDPR - Define Processors

A

A processor is responsible for processing personal data on behalf of a controller.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

UK GDPR - Processors - Give an example of the UK GDPR specific legal Obligations

A

you are required to maintain records of personal data and processing activities. You will have legal liability if you are responsible for a breach.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

UK GDPR - Controller- Give an example of the UK GDPR specific legal Obligations

A

If you are a controller, you are not relieved of your obligations where a processor is involved –
the UK GDPR places further obligations on you to ensure your contracts with processors comply with the
UK GDPR

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

When does the The UK GDPR apply to Processing?

A

The UK GDPR applies to processing carried out by organisations operating within the UK. It also applies
to organisations outside the UK that offer goods or services to individuals in the UK.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

When does the The UK GDPR NOT apply to Processing?

A

The UK GDPR does not apply to certain activities including:
*Processing covered by the Law Enforcement Directive,
*Processing for national security purposes and *Processing carried out by individuals purely for
personal/household activities.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is personal data?

A

Personal data only includes information relating to natural persons who:

  • Can be identified or who are identifiable, directly from the information in question; or
  • Who can be indirectly identified from that information in combination with other information.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

GDPR - How can Pseudonymised data help?

A

Pseudonymised data can help reduce privacy risks by making it more difficult to identify individuals, but
it is still personal data.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

The UK GDPR covers the processing of personal data in two ways:

A
  • *Personal data processed wholly or partly by automated means (that is, information in electronic form); and
  • *Personal data processed in a non-automated manner which forms part of, or is intended to form part of, a ‘filing system’ (that is, manual information in a filing system).
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Personal data - special categories

A

Personal data may also include special categories of personal data or criminal conviction and offences
data. These are considered to be more sensitive and you may only process them in more limited
circumstances.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is Anonymisation.

A

is a data processing technique that removes or modifies personally identifiable information; it results in anonymized data that cannot be associated with any one individual.
If personal data can be truly anonymised then the anonymised data is not subject to the UK GDPR. It is
important to understand what personal data is in order to understand if the data has been anonymised.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

GDPR - Deceased Person

A

Information about a deceased person does not constitute personal data and therefore is not subject to
the UK GDPR.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

GDPR - companies or public authorities

A

Information about companies or public authorities is not personal data.
However, information about individuals acting as sole traders, employees, partners and company
directors where they are individually identifiable and the information relates to them as an individual
may constitute personal data.