Module 4: Processing Personal Data Flashcards

1
Q

What is processing?

A

Any operation performed on personal data.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are the GDPR principles of processing?

A
Lawfulness, fairness and transparency
Purpose limitation
Data minimisation
Accuracy
Storage limitation
Integrity and confidentiality
Accountability
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What’s the territorial scope of the GDPR?

A

Processing of personal data where a controller or processor is in the EU

Processing of personal data of data subjects in the EU relating to offering of goods/services or monitoring behaviour in the EU

Processing of personal data by a controller not established in the EU but in a place where member state law applies by virtue of public international law

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is the material scope of the GDPR?

A

Article 2 - the processing of personal data wholly or partly by automated means or processing other than by automated means of personal data which forms part of a filing system.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are the lawful grounds for controllers to process data?

A
Consent
Contractual necessity
Legal obligation
Vital interests
Public interest
Legitimate interests
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is consent?

A
A clear affirmative act
Freely given
Specific and informed
Unambiguous
Indication of wishes
Written, electronic, oral or any other means
Conditional - can be withdrawn
Consent has elevated requirements, so is the least reliable basis for processing
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is the least reliable basis for processing?

A

Consent, due to elevated requirements and the ability to be withdrawn.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Consent for children’s data must be with authorisation of…

A

A parent or guardian (under 16 years old)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is legitimate interest?

A

Where processing is necessary and the interests are balanced against the data subject’s. The criteria for this is more restrictive.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Special category data is prohibited for processing except if…

A

Explicit consent has been given
It is in the context of employment
It supports the vital interests of the individual
For political, philosophical or religious purposes
The sensitive data is manifestly made public

How well did you know this?
1
Not at all
2
3
4
5
Perfectly