Topic 24: Other regulation affecting the advice process Flashcards
What are Oversight groups?
People or bodies with responsibility for ensuring firms meet various financial and regulatory requirements.
What are external auditors?
Inspect the firm’s financial accounts to ensure published financial reports are accurate and compiled in line with legislation and accounting standards. They are usually accountancy firms.
What are Internal Auditors?
Usually part of an in-house department, whose role is to assess how effectively the firm manages risk and the controls it has in place, and to identify any improvements needed to risk management processes and controls. Some firms outsource the function.
What are Trustees?
Responsible for holding and looking after trust assets in accordance with the trust deed, for the benefit of the beneficiaries. Examples in the context of financial services would be trustees of unit trust funds and occupational pension schemes. Pension scheme trustees have specific duties under the Pensions Acts of 1995 and 2004, and other trustees are subject to the requirements of the Trustee Act 1925 and the Trustee Investment Act 2000.
What is a Compliance Officer?
Firms regulated by the PRA and FCA must appoint a compliance officer to oversee the firm’s compliance with regulations and legislation. The position is a senior management function under the Senior Managers’ Regime, and is responsible for the production of a compliance manual, compliance records, dealing with the FCA and making sure staff meet FCA requirements.
What is Pension Protection Fund?
Compensates members of defined benefit occupational pension schemes when the employer becomes insolvent and the scheme cannot provide the promised member benefits. Funded by taking over and investing the assets of the insolvent employer’s scheme and charging a levy on other occupational schemes. It provides benefits for members at the scheme’s normal retirement date. Those who reached the scheme’s normal retirement date before the employer became insolvent receive 100% of the benefits they earned, while those who had not reached the normal retirement date are limited to 90%.
What are the six data protection principles?
1) Processed lawfully, fairly and in a transparent manner in relation to individuals.
2) Collected for specified, explicit and legitimate purposes and not further
processed in a manner that is incompatible with those purposes; further processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes shall not be considered
to be incompatible with the initial purposes.
3) Adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed.
4) Kept accurate and up to date. Every reasonable step must be taken to ensure
that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay.
5) Kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed, although archiving is allowed in certain circumstances.
6) Processed in a manner that ensures appropriate security of the personal
data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical
or organisational measures.
What is a Data Subject?
an individual (a natural person) whose personal data is processed.
What is Personal Data?
information that can directly or indirectly identify a natural
person. This information can be in any format.
What are Special Categories of Personal Data?
This data is more sensitive and so
needs more protection. Generally (although there are exceptions) such data
can only be processed if the individual has given explicit consent. Sensitive data includes information about an individual’s:
— race;
— religious beliefs;
— political persuasion;
— trade union membership;
— sexual orientation;
— health;
— biometric data;
— genetic data.
What is a Data Controller?
This is the ‘legal’ person who determines the purposes for which data are processed and the way in which this is done. The data controller is normally an organisation/employer, such as a company,
partnership or sole trader. They have prime responsibility for ensuring the
data protection requirements are adhered to.
What is the Data Processor?
This is a person who processes personal data on behalf of
the data controller.
An organisation must have a lawful basis for processing data. At least one of
the six must apply when processing personal data?
1) Consent – clear consent has been given by the individual to process their
personal data for a specific purpose.
2) Contract – the processing is necessary for a contract between the organisation
and the individual, or because the individual has asked for certain steps to be taken before entering into a contract.
3) Legal obligation – the processing is necessary for the organisation to comply with the law.
4) Vital interests – the processing is necessary to protect someone’s life.
5) Public task – the processing is necessary for the organisation to act in the public interest.
6) Legitimate interests – the processing is necessary for the organisation’s
legitimate interests or the legitimate interests of a third party, unless there is a good reason to protect the individual’s personal data which overrides
those legitimate interests.
A data subject has a number of rights, including the right to:
- access personal data through subject access requests (under UK GDPR, no
charge can generally be made for this); - correct inaccurate personal data;
- have personal data erased, in certain cases;
- object;
- move personal data from one service provider to another
In order to demonstrate compliance with the UK GDPR, an organisation must:
- establish a governance structure with roles and responsibilities;
- keep a detailed record of all data processing operations;
- document data protection policies and procedures;
- carry out data protection impact assessments for high-risk processing
operations.