Module 4 - Processing Personal Data Flashcards
What is data processing?
any operation or set of operations which is performed on personal data by any means
What do the OECD guidelines refer to?
Protection of privacy and transborder flow of personal data
How many principles encompass the OECD guidelines?
8 principles
What are the 8 principles of the OECD guidelines?
- Collection Limitation - limits the collection of PD to fair and lawful means with the consent of data subject
- Data Quality - relevant to the purpose intended, accurate, complete and up to date
- Purpose Specification - fit for purpose
- Use Limitation - limited use with consent/law
- Security safeguards - protect data from risks (loss, access, modification, destruction, disclosure)
- Openness
- Individual Participation - right to obtain, forget, disclose, correct
- Accountable - data controllers should have compliance with the above principles
What are GDPR principles?
- Purpose Limitation
- lawfulness and transparency of processing
- Data minimization and proportionality
- Accuracy
- Storage Limitation - relevant and necessary
- integrity and confidentiality - PD is secure
- Accountability - processing PD responsibly
What is the territorial scope of GDPR?
- when a controller or processor is in EU
- Services offered to EU data subjects in EU
- By a controller where member state law applies
What exclusions are there for GDPR applicability?
- Activities outside of the EU
- Law enforcement and public security
- Personal or household activities
What lawful grounds for the processing of personal data must exist?
- Consent
- Contract
- Legal Obligation
- Vital Interests
5 Public interest or official authority - Legitimate interests
What are the key factors linked to providing consent for the collection of personal data?
- Lawful processing
- Freely Given
- Specific
- Informed
- Unambiguous
- Children - parental concent needed 13-16 yrs of age
Exclusions to Material scope for GDPR include?
- Activities outside the scope of the EU law
- Law enforcement and public security
- Purely personal or household activites
Should material scope exclusions be considered narrowly or broadly.
They should be considered narrowly!
Out of the 6 lawful grounds/conditions for personal data to be processed, how many conditions need to need to be met for the processing of personal data to be lawful?
one
Which lawful processing criteria is used processing criteria is commonly used when a customer purchases a good or service?
Contract
The general starting point for the processing of special categories of data is prohibited. Ture or False?
True
Which exception to the prohibition on processing special categories of personal data must be explicit?
Consent