Module 3: Controllers & Processors Flashcards

1
Q

What is a data subject?

A

An individual about whom information is being processed.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is a controller?

A

An organisation or individual with the authority to decide how and why personal data about subjects is to be processed.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

How does GDPR define a data controller?

A

Article 4(7) - natural or legal person, public authority, agency or other body which alone or jointly with others determined the purposes and means of processing of personal data”

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

When might two organisations be considered joint controllers?

A

When both jointly determine the purposes and means for processing a data set.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Under Article 26, what are the obligations for joint controllers?

A

To determine their respective responsibilities for compliance with the obligations under GDPR in a compliant manner - e.g. data subject rights, DSARs, contact points and making the essence of their arrangement available to data subjects

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Irrespective of the terms of the arrangement between joint controllers, data subjects can…

A

Exercise their data rights against either controller.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

An example of joint controllers.

A

A travel agency sharing data with airlines and hotels; each controller is responsible for its own processing.

  • Two controllers sharing a black list
  • Fincrime / police
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is a processor?

A

An org or individual that processes data on behalf of the data controller (Article 4(8))

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Under Article 29, what does a processor do?

A

Processes on written instruction only.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Under Article 28, what does a processor do?

A

Provides a service to the controller and assists and informs them of any GDPR infringement.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Under Article 28, what does a processor have the obligation to do?

A

Protect personal data and ensure confidentiality and appropriate technical and organisational measures are in place.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Under Article 30, what must a processor do?

A

Demonstrate compliance by keeping a record of processing activities on all categories of personal data processing being carried out on behalf of the controller. It has enhanced obligations under GDPR.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Under Article 28, if a processor infringed on the regulation by determining the purposes and means of the processing, the processor will…

A

Be considered a controller in respect of that processing.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

In relation to processors, an organisation should…

A
  • Choose reliable processors
  • Maintain quality control and compliance throughout the duration of the arrangement
  • Frame the relationship in a contract or legally binding act
  • Do due diligence to check that the processor has appropriate technical and organisational measures to secure data, and a good knowledge of data protection, before signing any contract.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What should a controller check about a processor before entering a contract, aside from due diligence?

A

Whether they are under investigation, have any high profile recent breaches, their accreditations, policy frameworks and any sub processors

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What should a controller <> processor vendor contract include under Article 28?

A

The subject matter, duration and nature of processing, along with the types of personal data and categories of data subjects. It should also outline obligations and rights of. the controller, and processor responsibilities.

17
Q

A processor should…

A
Process on documented instructions only
Ensure confidentiality
Implement appropriate security
Seek consent from controller to engage further processors
Assist with breach notifications
Delete or return personal data
Assist the controller with DSRs
Demonstrate GDPR compliance
Contribute to audits and inspections
18
Q

How should an org manage vendor risk?

A

Third party due diligence
Contracts and agreements
The right to audit

19
Q

What is a Data Protection Authority (DPA)?

A

AKA a supervisory authority under GDPR - enforces privacy or data protection laws and regs (e.g. ICO)