Module 2 - Personal Data Flashcards
What is the main intention of the GDPR?
To protect personal data
What is personal data?
Article 4(1) of GDPR states: 1. Any information 2. related to 3. an identified or identifiable 4.natural person
Can ‘cookies’ be used as a source for the aggregation of personal data?
Yes, recital 30 mentions that unique identifiers and other collected information can be used to create profiles of natural persons and identify them.
What is anonymous data?
Anonymous data is not related to a personally identified attribute or identifier.
Anonymous data is not protected by the GDPR
What is Pseudonymous data?
Not fully anonymous - alias
detached PII data but PII can be still retrievable
data still subject to EU data protection laws
What is the advantage of using Pseudonymous data?
security measure to make the data less risky
Which article of GDPR describes special categories of personal data?
Article 9(1): Processing of personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person's sex life or sexual orientation shall be prohibited
What is the function of the 4 step test?
Determine if the data qualifies as personal data
What criteria is used to specifically describe personal data?
Any information relating to an identified or identifiable natural person
True of False: Personal data belongs to special categories. There is no grey area.
False, some personal data can be more sensitive and have an impact on individuals privacy rights and have a higher standard of protection. i.e. Article 9(1)
True or False: Anonymising personal data is always possible.
False, there will always be a chance that anonymous data can be collated to provide a profile of a natural person
Is Pseudonymous data is protected by GDPR?
Yes
When can personal data be published?
Under article 10 of GDPR:
Processing of personal data relating to criminal convictions and offences or related security measures based on Article 6(1) shall be carried out only under the control of official authority or when the processing is authorised by Union or Member State law providing for appropriate safeguards for the rights and freedoms of data subjects. Any comprehensive register of criminal convictions shall be kept only under the control of official authority.
How many articles are currently included within GDPR?
99