Module 2: Personal Data Flashcards
What is personal data? (4 step test)
Any information that related to an identified or identifiable natural person.
In the personal data definition ‘any information that related to an identified or identifiable natural person’ what does ‘any information’ refer to?
Any information collected or meant to be collected.
In the personal data definition ‘any information that related to an identified or identifiable natural person’ what does ‘relating to’ mean?
Relationship by content (i.e. name, job title, address) or any data that would be subject to someone’s privacy rights
In the personal data definition ‘any information that related to an identified or identifiable natural person’ what does ‘an identified or identifiable’ person mean?
Either that they are named or singled out by highlighting specific characteristics or are indirectly identifiable dependent on context
In the personal data definition ‘any information that related to an identified or identifiable natural person’ what is a ‘natural person’?
Someone who is born and living, not deceased.
Name four examples of personal data.
Name, age, gender, date of birth, languages spoken, marital status.
Is organisational information personal data?
Yes, it can be - e.g. business emails, identity verification information
What is special category data?
Article 9 -
Any personal data revealing race/ethnic origin, political opinion or religious beliefs
Any data uniquely identifying a natural person (e.g. genetic of biometric data)
Data concerning health, sex life or sexual orientation
Is data relating to criminal convictions and offenses considered special category?
No, but it is subject to limitations on processing (Article 10). It should be carried out only under the control of official authority or when processing is authorised by the inion law providing for appropriate safeguards for the rights and freedoms of data subjects.
What is anonymous data?
Data that cannot in any way be linked back to an identified or identifiable person and is no longer considered personal data under GDPR.
What is psuedoanonymous data?
Data that is not fully anonymous and can be linked back to an individual with context (e.g. a broken link) or detached aspects of data attributed to a specific individual.
Why might an organisation pseudoanonymise data?
As a security measure when data needs to be kept. Pseudo data is less risky, but is subject to data protection law, where anonymous data is not.