Module 4 - Processing Personal Data Flashcards

1
Q

What is data processing?

A

any operation or set of operations which is performed on personal data by any means

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What do the OECD guidelines refer to?

A

Protection of privacy and transborder flow of personal data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

How many principles encompass the OECD guidelines?

A

8 principles

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are the 8 principles of the OECD guidelines?

A
  1. Collection Limitation - limits the collection of PD to fair and lawful means with the consent of data subject
  2. Data Quality - relevant to the purpose intended, accurate, complete and up to date
  3. Purpose Specification - fit for purpose
  4. Use Limitation - limited use with consent/law
  5. Security safeguards - protect data from risks (loss, access, modification, destruction, disclosure)
  6. Openness
  7. Individual Participation - right to obtain, forget, disclose, correct
  8. Accountable - data controllers should have compliance with the above principles
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are GDPR principles?

A
  1. Purpose Limitation
  2. lawfulness and transparency of processing
  3. Data minimization and proportionality
  4. Accuracy
  5. Storage Limitation - relevant and necessary
  6. integrity and confidentiality - PD is secure
  7. Accountability - processing PD responsibly
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is the territorial scope of GDPR?

A
  1. when a controller or processor is in EU
  2. Services offered to EU data subjects in EU
  3. By a controller where member state law applies
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What exclusions are there for GDPR applicability?

A
  1. Activities outside of the EU
  2. Law enforcement and public security
  3. Personal or household activities
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What lawful grounds for the processing of personal data must exist?

A
  1. Consent
  2. Contract
  3. Legal Obligation
  4. Vital Interests
    5 Public interest or official authority
  5. Legitimate interests
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What are the key factors linked to providing consent for the collection of personal data?

A
  1. Lawful processing
  2. Freely Given
  3. Specific
  4. Informed
  5. Unambiguous
  6. Children - parental concent needed 13-16 yrs of age
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Exclusions to Material scope for GDPR include?

A
  1. Activities outside the scope of the EU law
  2. Law enforcement and public security
  3. Purely personal or household activites
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Should material scope exclusions be considered narrowly or broadly.

A

They should be considered narrowly!

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Out of the 6 lawful grounds/conditions for personal data to be processed, how many conditions need to need to be met for the processing of personal data to be lawful?

A

one

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Which lawful processing criteria is used processing criteria is commonly used when a customer purchases a good or service?

A

Contract

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

The general starting point for the processing of special categories of data is prohibited. Ture or False?

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Which exception to the prohibition on processing special categories of personal data must be explicit?

A

Consent

How well did you know this?
1
Not at all
2
3
4
5
Perfectly