Tutorial 8 Flashcards

1
Q

what is the DPA 2018?

A

data protection act 2018

legislation enforced by the information commissioner’s office (ICO) to protect personal data processing and data stored on computers, digital media etc.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

what does the DPA 2018 define?

A

defines how organisations, businesses and governments use personal data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

anonymisation = ?

A

the process of rendering data into a form which doesn’t identify individuals

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

consent = ?

A

freely given, specific, informed and unambiguous indication of the subject’s wishes to agree to the processing of their personal data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

data breach = ?

A

a breach of security leading to the accidental/unlawful destruction/loss/misuse of data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

data controller = ?

A

natural or legal person which determines the purposes of the processing of personal data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

data processor = ?

A

a natural or legal person which processes personal data on behalf of the controller

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

data protection impact assessment (DPIA) = ?

A

a method of identifying and addressing privacy risks in compliance with data protection laws

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

data protection officer (DPO) = ?

A

a role within an organisation responsible for enabling compliance with data protection legislation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

data sharing agreement = ?

A

legal contract outlining the information that parties agree to share

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

data subject = ?

A

any living individual who is the subject of personal data held by an organisation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

employee = ?

A

a full time or part time paid officer of an organisation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

filing system = ?

A

a structured set of personal data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

information owner = ?

A

a member of staff that has responsibility for a set of information

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

personal data = ?

A

information relating to an identifiable natural person

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

processing = ?

A

operations which is performed on personal data

(e.g., collection, recording, structuring, organisation, storage etc.)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

profiling = ?

A

any form of automated processing of personal data intended to evaluate certain aspects relating to personal data of a natural person

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

restricted = ?

A

a classification of information which (if disclosed to unauthorised recipients) could have a negative impact on the rights of the individuals

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

third party = ?

A

natural or legal person other than the data subject, controller or processor

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

what are the principles of the DPA 2018?

A
  • lawfulness, fairness & transparency
  • purpose limitation
  • data minimisation
  • accuracy
  • storage
  • security
  • accountability
21
Q

lawfulness, fairness & transparency principle of DPA 2018?

A

organisations & controllers must be transparent when seeking individuals for data collection

22
Q

purpose limitation principle of DPA 2018?

A

specifies that personal data must be used for the specific purpose for which the data subjects gave consent

23
Q

data minimisation principle of DPA 2018?

A

collect only the necessary and relevant data - nothing more

24
Q

accuracy principle of DPA 2018?

A

controllers must verify that the data they process & collect is accurate - not misleading

25
storage principle of DPA 2018?
controllers shouldn't store personal data for longer than necessary
26
security principle of DPA 2018?
organisations & controllers must ensure personal data is securely kept
27
accountability principle of DPA 2018?
every organisation that stores or processes personal data must comply with regulatory obligations
28
GDPR?
general data protection regulation encompasses the processing of personal data wholly or partly by automated means
29
since the UK left EU, what happened to GDPR?
the UK now has its own version of the GDPR called UK-GDPR same as normal GDPR but its complemented by the DPA 2018 which provides UK specific details
30
under the GDPR rights, what are the two categories of data?
personal data sensitive personal data
31
personal data = ?
information that helps identify the person related to some degree of accuracy
32
what happens if sensitive personal information is disclosed?
in contrast to GDPR breach, if disclosed or misused, disclosure of sensitive personal information can result in data theft or identity fraud sensitive personal information needs an extra layer of security controls (e.g., encrypted, password-protected etc.)
33
examples of sensitive personal data
biometric data (individual's physical characteristics e.g., DNA, hand geometry, facial patterns) health data (medical history) genetic data (data associated with inherited characteristics) individual data (political views, sexual orientation) financial data (e.g., credit card details) classified data business-related data web data (e.g., IP Address)
34
online selling / e-commerce = ?
the process of selling goods/services via an internet or mobile app
35
before customers place an order, what must be made clear by online traders?
- 'pay now' button - clear delivery options - clear costs - language options - VAT number - any contingent conditions
36
when must online traders confirm the contract?
ASAP e.g., with an email
37
after an order is placed, an e-commerce company must...
- confirm the contract ASAP - provide contract copy - deliver goods within 30 days (unless agreed otherwise)
38
distance selling = ?
selling goods/services through digital TV, by mail or by phone/text message
39
what are the rules regarding accepting returns & giving refunds?
consumers have a right to cancel their order for a limited time even if the goods aren't faulty refund must be offered if informed within 14 days of receipt company must refund customer within 14 days
40
the consumer rights act 2015?
outlines what rights a consumer has and what company's obligations are as a goods/services provider in the event of a dispute
41
rules regarding website by law?
must make reasonable adjustments to be suitable for all, including disabled users
42
must every website contain a 'website's terms of use'
yes including conditions that the customer agrees to when using the company's website
43
payment card industry (PCI) compliance?
offering customers multiple ways to pay provides a more convenient checkout experience with less friction online traders must ensure this is secure e.g., security measure like payment card industry data security standard (PCI DSS)
44
how often must signatures for traders be by ink in the UK?
rarely normally a name at the end of an email suffices
45
which documents can be signed electronically?
- commercial contracts - employment contracts - corporate resolutions - NDA's - consumer transactions - procurement
46
which transactions can't be signed electronically?
- wills/testamentary dispositions - real estate - banking - lending - statutory agreements - government filings
47
what are the consequences of non-compliance with a particular method of signing?
the document or transaction is invalid
48
computer misuse act 1990?
protects personal data held by organisations from unauthorised access and modification act makes the following illegal - unauthorised access to computer material - unauthorised access to computer materials with intent to commit a further crime - unauthorised modification of data - supplying anything which can be used in computer misuse offences e.g., hacking, blackmail, viruses, computer fraud
49
failure to comply with the computer misuse act leads to...
fines and potentially imprisonment