MIDTERM EXAM Flashcards
Formally known as the Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data.
Convention 108
The entities that must comply with the GDPR are
organizations, entities, and individuals that process personal data and are located within the EU or process personal data of individuals within the EU.
TRUE OR FALSE
TRUE
Convention 108 Key Principles
- PROTECTION OF PRIVACY
- SUPERVISORY AUTHORITIES
Requires that any information addressed to the public or to the data subject be concise, easily accessible and easy to understand, and that clear and plain language and, additionally, where appropriate, visualization be used.
TRANSPARENCY PRINCIPLE
The TRANSPARENCY PRINCIPLE requires that any information addressed to the public or to the data subject be concise, easily accessible and easy to understand, and that clear and plain language and, additionally, where appropriate, visualization be used. TRUE OR FALSE
TRUE
Personal data should only be collected for specified, explicit, and legitimate purposes and not further processed in a manner that is incompatible with those purposes.
PURPOSE LIMITATION PRINCIPLE
Collecting only necessary data for intended purposes
DATA MINIMIZATION PRINCIPLE
Personal Data is accurate and suitable for the purpose for which it is processed.
Integrity
requires you to take responsibility for what you do with personal data and how you comply with the other principles
Accountability Principle
refers to the legal and organizational measures designed to safeguard personal data against unauthorized access, use, alteration, or destruction.
DATA PROTECTION
A law in the European Union (EU) that came into effect on ____. It aims to protect the personal data of EU citizens and residents.
May 25, 2018
A law created to strengthen and unify data protection for individuals within the EU. It aims to protect the personal data of EU citizens and residents.
GDPR
GDPR Data Protection Principles
- Lawfulness, fairness, and transparency
- Purpose limitation
- Data minimization
- Accuracy
- Storage limitation
- Integrity and confidentiality (security)
- Accountability
Rights of Data Subjects
- Right to be informed
- Right of access
- Right to rectification
- Right to erasure (right to be forgotten)
- Right to restrict processing
It involves the transmission of personal or sensitive data from one country to another.
CROSS-BORDER DATA TRANSFERS