GDPR Core Flashcards

Copied organization from this deck: https://www.brainscape.com/packs/cipp-e-10493977 Goal is to prepare for exam my way, but I agree with the organization used by that creator. This is a different approach at the same problem.

1
Q

Personal Data (EU)

A

Info relating to an identified or identifiable natural person.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

How can a natural person be identified?

A

Directly or indirectly

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Attributes that can be used to identify a person

A

ID Number

Factors relating to physical, psychological, mental, economic, cultural, or social identity.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are these?

ID Number
Factors relating to physical, psychological, mental, economic, cultural, or social identity.

A

Personal data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Natural personal

A

An actual human to whom data applies

Schellman.com definition

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Data processing

A

Any operations performed on personal data.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What are these examples of regarding personal data?

Collection
Recording
Storage
Adaptation
Retrieval
Consultation
Disclosure
Alignment/Combination
Erasure
A

Data processing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Right to restriction

A

Individual’s right to limit/prohibit an entity from processing personal data.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Profiling

A

Any form of automated processing of personal data to evaluate personal aspects.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What does profiling do?

A

Make predictions about work performance, credit, health, interests, behavior, location, etc.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Automated processing of personal data to make predictions is called…

A

Profiling

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Pseudonymisation

A

Processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

How do you prevent pseudonymisation from being reversed?

A

Keep identifying information separate from pseudonymized data using technical and organizational measures.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Who does pseudonymized data apply to?

A

Identified or identifiable natural persons.

Data subjects

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Data controller

A

Determines the purposes and means of the processing of personal data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Who can be a data controller? (4+1)

A

Natural or legal person
Public authority
Agency
Any other body alone or jointly that determines purpose and means of processing.

May be determined by EU or member state law.

17
Q

Data processor

A

Processes personal data on behalf of the controller

18
Q

Who can be a data processor?

A

Natural or legal person (other than an employee of the controller)
Public authority
Agency

19
Q

Can an organization be both a processor and controller?

A

Yes

20
Q

What can a natural or legal person, public authority, or

agency be? (4)

A

Data Controller
Data Processor
Data Recipient
Third Party

21
Q

Data recipient

A

A person/entity to which personal data is disclosed, except public authorities in an inquiry in accordance with EU/state law.

22
Q

Who is not regarded as a data recipient?

A

Public authorities in the “framework” of an inquiry (in accordance with law).