Topic 24 Other Regulation Affecting The Advice Process Flashcards
Which organisation is responsible for the prevention of fraud arising from identity theft?
Financial Conduct Authority (FCA)
What is the main EU Legislation for online activity and the rise of social media that came into force in May 2016?
General Data Protection Regulation (GDPR)
The primary UK legislation for Data Protection is what?
Data Protection Act 2018
Personal data is defined as an individual who can be identified by?
- Name
- Identification Number
- Location Data
- Online Identifier
The below are what in relation to General Data Protection Regulation (GDPR)?
- Processed lawfully, fairly & in a transparent manner in relation to all individuals
- Collected for specied, explicit & legimate purposes & not further processed in a manner that is incompatible with those purposes
- Adequate, relevent & limited to what is necessary in relation to the purposes for which they are processed
UK GDPR
The below are what in relation to General Data Protection Regulation (GDPR)?
- Kept accurate & up to date
- Kept in a form that permits identification of data subjects for no longer than is necessary
- Processed in a manner that ensures appropriate security of the personal data
UK GDPR
Which UK GDPR definition is this?
An individual (natural person) who’s personal data is processed?
Data Subject
Which UK GDPR definition is this?
Information that can directly or indirectly identity a natural person. Information can be in any format
Personal data
Special categories of personal data require the individuals consent.
True or False
True
What are the below in relation to UK GDPR?
- Race
- Religious Beliefs
- Political persuasion
- Trade Union Membership
Special categories of personal data
What are the below in relation to UK GDPR?
- Sexual Orientation
- Health
- Biometric data
- Genetic data
Special categories of personal data
Processing covers all aspects of owning data but what does it include?
- Owning data
- Recording of data
- Organisation or alteration of data
- Disclosure of data
- Destruction of data
What are the below in relation to UK GDPR?
The “legal person” determines the purposes for which data are processed. Data controller is normally an organisation/ employer
Data Controller
What is a data processor?
Person who processes personal data on behalf of the data controller
What are the 6 lawful basis for data processing?
- Consent
- Contract
- Legal Obligation
- Vital Interests
- Public Task
- Legitimate Interests
The below are what in relation to a data subject?
- Access personal data
- Correct inaccurate person data
- Have personal data erased
- Object
- Move personal data from one service provider to another
Rights a Data Subject has
The below are what in relation to UK GDPR
- Establish a governance structure with roles and responsibilities
- Keep a detailed record of data processing operations
- Document data protection policies & procedures
- Carry out data protection impact assessments for high risk processing operations
How an organisation demonstrates compliance with UK GDPR
The below are what relating to UK GDPR?
- If receiver is located in a third country
- Is an international organisation
- Particular country covered by UK “adequacy rules”
When restricted transfers are permitted
Who is responsible for the overseeing of UK GDPR?
Information Commissioner
Which of the Information Commissioner’s power is this?
Requiring organisations to provide the Information Commissioner’s office with specified information within a certain period
Serve Information Notices
Which of the Information Commissioner’s power is this?
Committing an organisation to a particular course of action in order to improve its compliance
Issue Undertakings
Which of the Information Commissioner’s power is this?
Requiring organisations to take (or refrain from taking) specified steps to ensure they comply with the law
Serve enforcement notices & “stop now” orders when there has been a breach
Which of the Information Commissioner’s power is this?
To check organisations are complying
Conduct consensual assessments (audits)
Which of the Information Commissioner’s power is this?
To conduct compulsory audits to assess whether organisations processing of personal data follows good practice
Serve assessment notices
Which of the Information Commissioner’s power is this?
Notification that the organisation is subject to a financial penalty as a result of a serious breach of UK GDPR
Issue Monetary Penalty Notices
Which of the Information Commissioner’s power is this?
Those who commit criminal offences under UK GDPR
Prosecute
Which of the Information Commissioner’s power is this?
A temporary or permanent ban on data prosecution can be imposed
Issue a ban
The below are what in relation to UK GDPR?
- Failure to comply with information or enforcement notice (Data Controller)
- Failure to make a proper notification to the information controller
- Processing of data without authorisation from the commissioner
- Intentionally or recklessly re-identifying individuals from data that is pseudonmised
Criminal offences under UK GDPR
What is the maximum penalty for criminal offences under UK GDPR for a firm?
Higher of
- £17.5 Million
- 4% of an organisation’s total annual worldwide revenue
The below is the responsibility of who?
- “automatic enrolment” of staff onto work based pension scheme
- Protect the benefits of personal pension schemes & people’s savings
- Protect the benefits of personal pension schemes where this is a direct pay arrangement
- Promote good adminstration of work based pension schemes
The Pensions Regulator (TPR)
The below is the responsibility of who?
- Reduce the risk of situations arising that could lead to claims from the Pension Protection Fund
- Maximise employer compliance with duties & safeguards under Pensions Act 2008
- Minimise any adverse impact of the sustainable growth of an employer
The Pensions Regulator (TPR)
The Pensions Regulator aims to consider the combined effect of what?
- Likelihood of an event occuring
- Impact of the event on the scheme and it’s members
The Pensions Regulator is required to issue what?
Issue voluntary codes of practice on a range of subjects
Which power of the Pensions regulator is this?
- Identifying & investigating risks
- Requiring all schemes to make regular returns to the regulator
- Requiring trustees/scheme managers give notification of any changes to important information such as type of benefit provided by the scheme
- Regulator be informed quickly if the scheme cannot meet it’s funding requirements
Investigating Schemes
Which power of the Pensions regulator is this?
- Requiring specific action be taken to improve matters within a certain period of time
- Recovering unpaid contributions from an employer who does not pay them into a scheme within the required period
- Disqualifying trustees who are considered not fit & proper persons
- Imposing finest or prosecuting offences in criminal courts
Putting this right