Principles Related To DP Flashcards

1
Q

Explain lawfulness in the context of GDPR

A

Identification of a legal basis for processing, which includes
- consent of data subject
- performance of a contract to which the data subject is a party
- controllers compliance with legal obligation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Explain fairness in the context of GDPR

A
  • Avoiding negative impact on data subjects
  • Considering reasonable expectation of privacy
  • Not misleading or deceiving data subject
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Explain transparency in the context of GDPR

A
  • compliance with obligations on information provision to data subjects
  • Clear, plain language accessible, and honest information
  • Avoiding opacity (invisible processing)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Explain purpose limitation

A

Personal data shall be collected for specified explicit and legitimate purposes

Controllers have to inform data subjects about purposes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Explain data minimisation

A

Adequate sufficient to properly fulfil controllers purpose

Relevant rational link to purpose

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Explain accuracy in the context of GDPR

A

Contextual, meaning

Controllers should ensure that source and status of personal data is clear

Carefully consider any challenges to the accuracy of information

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Explain storage limitations in the context of GDPR

A

Considering retention periods retention policies by using erasure and analyzation

Exceptions apply

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Explain, integrity and confidentiality i context of GDPR

A
  • Controllers and processors to implement appropriate security measures
  • Security measures must be proportional to the risks associated with processing activities
  • Factors that term in the appropriate level of security include nature of the data and potential impact on individuals, rights and freedom
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Explain how organisations are held accountable

A
  • Data protection as risk management policy
  • Data protection by design
  • Data protection by default
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Name and describe all GDPR personae

A

Data subjects: Individuals to whom the data relates.

Controllers: Entities that determine purposes and means of processing.

Processors: Entities that process data on behalf of a controller.

Data protection officers (DPOs): Individuals responsible for ensuring GDPR compliance.

Supervisory authorities: Public bodies responsible for enforcing GDPR.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What are Joint controllers

A

Two or more entities that jointly determine data processing purposes and means, each responsible for GDPR compliance with a legal basis for processing and a joint agreement outlining their responsibilities and obligations.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly