General Flashcards
Define “personal data breach”
A breach of security leading to the accidental, unauthorised disclosure of or access to personal data transmitted, stored or otherwise processed.
What type of consent is required?
Express, informed and opted in.
How must consent be recorded?
It must be documented.
What does GDPR require for consent withdrawal?
It has to be as easy as giving consent.
Can a data subject withdraw consent?
Yes at any time, any data can be removed. Any UK or EU citizen can request removal.
The right to remove all data for a subject is called?
Right to be forgotten.
For which reason may data be retained?
Only when there is regulatory or statutory obligation to do so. Retention cannot be for marketing or future sales.