Week 8: Legal Issues and GDPR Principles Flashcards
*add cards on lawful basis of processing, and cards testing the acronyms for both*
What is a data controller
Determines the purposes and means for using personal data. If you can answer why personal data is being used, you are likely a data controller.
What is a data processor
Often a sub-contracted company that handles personal data but does not determine its purpose. They control how data is stored and transferred.
What is a data subject
Identified or identifiable natural persons whose data is collected.
GDPR Principle: Lawfulness
Lawfulness, Fairness, and Transparency:
Personal data must be processed lawfully, fairly, and transparently.
GDPR Principle: Purpose Limitation
Purpose Limitation:
Personal data must be collected for specified, explicit, and legitimate purposes, and not further processed incompatibly with those purposes.
GDPR Principle: Data Minimisation
Data Minimisation: Data must be adequate, relevant, and limited to what is necessary for its purpose.
GDPR Principle: Accuracy
Accuracy: Data must be accurate and, where necessary, kept up to date.
GDPR Principle: Storage Limitation
Storage Limitation: Data must not be kept in identifiable form longer than necessary.
GDPR Principle: Integrity and Confidentiality
Integrity and Confidentiality (Security Principle): Data must be secured against unauthorised access, accidental loss, destruction, or damage.
GDPR Principle: Accountability
Accountability: Controllers must demonstrate compliance with the data protection principles.
Lawful Basis for Processing Under GDPR: Public Interest
Public Interest:
Processing is required for a task carried out in the public interest or under official authority.
Lawful Basis for Processing Under GDPR: Consent
Consent:
The data subject has provided clear consent for specific purposes.
Lawful Basis for Processing Under GDPR: Legal Obligation
Legal Obligation:
Processing is required to comply with a legal obligation.
Lawful Basis for Processing Under GDPR: Legitimate Interest
Legitimate Interest:
Processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.
Lawful Basis for Processing Under GDPR: Contract
Contract:
Processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract.