Unit 3 Database - GDPR Data Protection Flashcards

1
Q

What is the General Data Protection Regulation (GDPR)?

A

The GDPR is a set of rules designed to give EU citizens greater control over their personal data. It replaces and strengthens existing data protection laws, ensuring they remain relevant in the internet age.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

When did GDPR come into effect?

A

GDPR came into force on May 25, 2018.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is UK GDPR?

A

After the UK left the European Union, a version of GDPR known as UK GDPR was implemented as UK law.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are the six key principles of GDPR regarding data processing?

A
  1. Processed lawfully, fairly, and transparently
  2. Used for the declared purpose only
  3. Limited to the necessary data
  4. Accurate
  5. Not kept longer than necessary
  6. Held securely
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Who is a Data Subject under GDPR?

A

The individual whose personal data is being collected and processed.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What qualifies as Personal Data?

A

Any information that can directly identify an individual, such as their name, address, IP address, or device ID.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Who is a Data Controller?

A

An organization or company that determines how and why personal data is processed.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Who is a Data Processor?

A

A third-party entity that processes personal data on behalf of a Data Controller.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is a Privacy Notice?

A

A document provided by the Data Controller informing the Data Subject about how their data will be processed and for how long.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What are the 8 rights of Data Subjects under GDPR?

A
  1. Right to be informed
  2. Right to access
  3. Right to rectification
  4. Right to erasure
  5. Right to restrict processing
  6. Right to data portability
  7. Right to object
  8. Rights related to automated decision-making and profiling
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Under what circumstances must personal data be erased?

A
  1. No longer needed for the original purpose
  2. Consent is withdrawn
  3. The Data Subject objects to processing
  4. Data was processed unlawfully
  5. Legal requirement to delete it
  6. Data was collected from a child without parental consent
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is the Right to Data Portability?

A

The right to move personal data between different services, such as downloading shopping history from a retailer.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is the Right to Object?

A

The right to object to data processing for direct marketing, research, or where the processing is based on ‘legitimate interest’.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is the Right to Challenge Automated Decision Making?

A

Data subjects can:
1. Request a human review of decisions
2. Express their viewpoint
3. Obtain an explanation of decisions
4. Challenge the decision

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What are the lawful bases for processing data under GDPR?

A
  1. Consent
  2. Contract
  3. Legal Obligation
  4. Vital Interest
  5. Public Task
  6. Legitimate Interest
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is a Data Breach?

A

A security incident that results in personal data being lost, accessed by unauthorized parties, corrupted, or made unavailable.