Topic 24 Other Regulation Affecting The Advice Process Flashcards
Which organisation is responsible for the prevention of fraud arising from identity theft?
Financial Conduct Authority (FCA)
What is the main EU Legislation for online activity and the rise of social media that came into force in May 2016?
General Data Protection Regulation (GDPR)
The primary UK legislation for Data Protection is what?
Data Protection Act 2018
Personal data is defined as an individual who can be identified by?
- Name
- Identification Number
- Location Data
- Online Identifier
The below are what in relation to General Data Protection Regulation (GDPR)?
- Processed lawfully, fairly & in a transparent manner in relation to all individuals
- Collected for specied, explicit & legimate purposes & not further processed in a manner that is incompatible with those purposes
- Adequate, relevent & limited to what is necessary in relation to the purposes for which they are processed
UK GDPR
The below are what in relation to General Data Protection Regulation (GDPR)?
- Kept accurate & up to date
- Kept in a form that permits identification of data subjects for no longer than is necessary
- Processed in a manner that ensures appropriate security of the personal data
UK GDPR
Which UK GDPR definition is this?
An individual (natural person) who’s personal data is processed?
Data Subject
Which UK GDPR definition is this?
Information that can directly or indirectly identity a natural person. Information can be in any format
Personal data
Special categories of personal data require the individuals consent.
True or False
True
What are the below in relation to UK GDPR?
- Race
- Religious Beliefs
- Political persuasion
- Trade Union Membership
Special categories of personal data
What are the below in relation to UK GDPR?
- Sexual Orientation
- Health
- Biometric data
- Genetic data
Special categories of personal data
Processing covers all aspects of owning data but what does it include?
- Owning data
- Recording of data
- Organisation or alteration of data
- Disclosure of data
- Destruction of data
What are the below in relation to UK GDPR?
The “legal person” determines the purposes for which data are processed. Data controller is normally an organisation/ employer
Data Controller
What is a data processor?
Person who processes personal data on behalf of the data controller
What are the 6 lawful basis for data processing?
- Consent
- Contract
- Legal Obligation
- Vital Interests
- Public Task
- Legitimate Interests
The below are what in relation to a data subject?
- Access personal data
- Correct inaccurate person data
- Have personal data erased
- Object
- Move personal data from one service provider to another
Rights a Data Subject has
The below are what in relation to UK GDPR
- Establish a governance structure with roles and responsibilities
- Keep a detailed record of data processing operations
- Document data protection policies & procedures
- Carry out data protection impact assessments for high risk processing operations
How an organisation demonstrates compliance with UK GDPR
The below are what relating to UK GDPR?
- If receiver is located in a third country
- Is an international organisation
- Particular country covered by UK “adequacy rules”
When restricted transfers are permitted
Who is responsible for the overseeing of UK GDPR?
Information Commissioner
Which of the Information Commissioner’s power is this?
Requiring organisations to provide the Information Commissioner’s office with specified information within a certain period
Serve Information Notices
Which of the Information Commissioner’s power is this?
Committing an organisation to a particular course of action in order to improve its compliance
Issue Undertakings
Which of the Information Commissioner’s power is this?
Requiring organisations to take (or refrain from taking) specified steps to ensure they comply with the law
Serve enforcement notices & “stop now” orders when there has been a breach
Which of the Information Commissioner’s power is this?
To check organisations are complying
Conduct consensual assessments (audits)
Which of the Information Commissioner’s power is this?
To conduct compulsory audits to assess whether organisations processing of personal data follows good practice
Serve assessment notices