GDPR (and Private Client) [15] Flashcards

1
Q

GDPR (and Private Client)

What piece of UK legislation came into force which applied the General Data Protection Regulation (EU) 2016/679? [1]

A

The UK Data Protection Act 2018

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

GDPR (and Private Client)

What is the maximum penalty for breach of the GDPR? [1]

A

Penalties for a failure to comply with the GDPR (and the Data Protection Act) can be a maximum of 20 million Euros, or 4% of global turnover of business, whichever is the greater.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

GDPR (and Private Client)

Explain what the GDPR applies to. [1]

A

The GDPR regulates the processing of ‘personal’ data’.

‘Personal data’ is data which can lead to the identification of an individual.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

GDPR (and Private Client)

Which organisations must document their compliance with the GDPR? [2]

A

Organisations with 250 or more employees must document all their processing activities.

Smaller organisations only need to document certain processing activities which are not, inter alia, occasional (more than just a one-off, or only occasional).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

GDPR (and Private Client)

Do data controllers or data processors have to comply with the GDPR? [1]

A

Data controllers have the primary responsibility to comply with the GDPR. Data processors are permitted to process the data as instructed by the data controller

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

GDPR (and Private Client)

What three key principles does Article 5 GDPR set out? [3]

A

(i) Personal data must be collected only for a specified, explicit and legitimate purpose.
(ii) Personal data must be not be kept in a form which permits identification of data subjects for any longer than is necessary for the purposes for which the data is processed.
(iii) Personal data must be processed in a manner that ensures its appropriate security.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

GDPR (and Private Client)

Inter alia, name three key lawful permitted grounds for processing personal data? [3]

A

Lawful grounds for processing data include (inter alia): (i) Consent; (ii) Contractual obligation; and (iii) Legal obligation.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

GDPR (and Private Client)

What do Articles 13 and 14 GDPR require? [1]

A

Articles 13 and 14 require information to be provided to the data subjects, typically in the form of privacy notices which set out statue mandated information (e.g. data processing details, reason for processing, data stored, data subjects’ rights, etc)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

GDPR (and Private Client)

True or false: “PRs and trustees will be data controllers and have to comply with the GDPR (including in respect to privacy notices) where they store and process individuals’ personal data)”? [2]

A

True, unless data is only processed on a one-off or very occasional basis.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly