Optional - Data Management (L3) Flashcards
What is GDPR?
GDPR is the General Data Protection Regulation (2016), that came into effect on the 25th May 2018. It aims to create a single data protection regime for the European Union
What Act Implemented the GDPR in the UK?
The Data Protection Act (2018), which replaces the Data Protection Act 1998 after 20 years.
What do you need to do if you have a data breach?
Notify the Information Commissioners Office (ICO) within 72 hours of the breach occurring.
What are the fines for non-compliance with UK GDPR?
For serious breaches of the data protection principles, ICO power to issue fines of up to £17.5 million or 4% of your annual worldwide turnover, whichever is higher
What are the 8 Individual Rights Under GDPR?
- Right to Be Informed of info being held
- Right of Access
- Right of Rectification
- Right to Erasure
- Right to Restrict Processing
- Right to Data Portability
- Right to Object
- Right to Automated Decision Making
BARE ROPA
When was the Freedom of Information Act Enforced, and what does it do?
The freedom of information Act came into effect in 2000, it allows an individual to request access to information held by a public body. The public body is required to provide that information (normally in 20 working days) in the requested format, however they can charge a fee for this.
Give me an example of how your company is compliant with GDPR
On marketing emails, we give people the right to be removed from our database.
Does your company tell people how their data is stored?
Yes, our website gives detail on our ‘Fair Processing Notices’ which outlines:
* our purpose of collecting personal data
* how to unsubscribe from marketing communication
* special catergories of data are necessary for fulfilling legal obligations relating to AML
What Act Implemented the GDPR in the UK?
The Data Protection Act (2018), which replaces the Data Protection Act 1998 after 20 years.
What is GDPR?
GDPR is the General Data Protection Regulation (2016), that came into effect on the 25th May 2018 as part of the UK Data Protection Act.
It aims to create a single data protection regime for the European Union
What do you need to do if you have a data breach?
Notify the Information Commissioners Office (ICO) within 72 hours of the breach occurring.
What are some examples of data security technologies?
Disk encryption (encrypting data on a secure hard disk drive)
regular back-ups offsite
password protection
use of anti-virus software protection
firewalls
VPNS (Virtual Private Networks)
What is a firewall?
Network security device that monitors traffic to or from your network
What is copyright?
A set of exclusive rights granted to the author or creator of any original work inc. the right to copy. Form of intellectual property
What is triangulation?
Triangulation is the process of verifying data from multiple sources to validate any data collected
Who polices the Data Protection Act and UK GDPR?
Information Commissioners Office (ICO)