GDPR Flashcards

1
Q

What measures does the practice need to take to ensure data protection is being taken seriously?

A
  • data protection audits
  • policy reviews
  • privacy impact assessments
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

When would you need to carry out a privacy impact assessment?

A

When planning a new initiative which involves high risk data processing activities e.g processing special categories of personal data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is the idea behind a PIA?

A

Is to identify and minimise non-compliance risks

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is an audit?

A

Reviewing and documenting the personal data we hold, identify the source and who it is shared with

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is a benefit of an audit?

A

It can demonstrate and how well we comply with the data protection principles and highlight red flags which need attention

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is a DPO?

A

Data protection officer

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Who needs a DPO?

A

All practices

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What must the DPO have?

A

Specific knowledge in that sector, the employer must help maintain this knowledge with specific training

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What are some of the DPOs tasks?

A
  • advising colleagues and monitoring the practices compliance including staff training
  • monitoring the documentation, notification and communication of data breaches
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Who can be the DPO?

A

Either an employee or a hired contractor

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What will new starters receive?

A

Data protection training before having access to personal date

Existing staff with will receive regular and refresher training

Record of who and what training employees have completed should be kept to ensure everyone gets sufficient training

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

When may personal data be processed?

A
  • with consent
  • where the processing is necessary for a contract
  • where processing is necessary for compliance with a legal obligation
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is freely given consent?

A

The consent must be freely given and capable of being withdrawn at any time

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is specific consent?

A

Separate consents must be obtained for different processing operation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is fully informed consent?

A

You should clearly explain to individual what they are consenting to and of their right to withdraw consent

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What are the main legal rights under the GDPR?

A
To have information erased 
To have inaccuracies corrected 
To prevent direct marketing 
To prevent automated decision-making and profiling 
Data portability
17
Q

What is subject access request? (SAR)

A

It allows individuals to ask to give them a copy of their personals data together with other information of how it’s being processed by the practice

18
Q

Under the GDPR what are the main changes?

A
  • right to withdraw info is now free (was £10) but not in all cases
  • manifestly unfounded or excessive requests can now be charged for or refused
  • to supply data retention periods and have the inaccurate data correct
  • if the practice removes SAR you will need to have policies and procedures in place to demonstrate why refusal meets these criteria
19
Q

When can children consent?

A

16 but can be lowered to 13 by a member state

Ultimately, u13 can never consent to the processing of their personal data