Week 8: Legal Issues and GDPR Principles Flashcards

*add cards on lawful basis of processing, and cards testing the acronyms for both*

1
Q

What is a data controller

A

Determines the purposes and means for using personal data. If you can answer why personal data is being used, you are likely a data controller.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is a data processor

A

Often a sub-contracted company that handles personal data but does not determine its purpose. They control how data is stored and transferred.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is a data subject

A

Identified or identifiable natural persons whose data is collected.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

GDPR Principle: Lawfulness

A

Lawfulness, Fairness, and Transparency:
Personal data must be processed lawfully, fairly, and transparently.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

GDPR Principle: Purpose Limitation

A

Purpose Limitation:
Personal data must be collected for specified, explicit, and legitimate purposes, and not further processed incompatibly with those purposes.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

GDPR Principle: Data Minimisation

A

Data Minimisation: Data must be adequate, relevant, and limited to what is necessary for its purpose.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

GDPR Principle: Accuracy

A

Accuracy: Data must be accurate and, where necessary, kept up to date.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

GDPR Principle: Storage Limitation

A

Storage Limitation: Data must not be kept in identifiable form longer than necessary.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

GDPR Principle: Integrity and Confidentiality

A

Integrity and Confidentiality (Security Principle): Data must be secured against unauthorised access, accidental loss, destruction, or damage.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

GDPR Principle: Accountability

A

Accountability: Controllers must demonstrate compliance with the data protection principles.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Lawful Basis for Processing Under GDPR: Public Interest

A

Public Interest:
Processing is required for a task carried out in the public interest or under official authority.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Lawful Basis for Processing Under GDPR: Consent

A

Consent:
The data subject has provided clear consent for specific purposes.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Lawful Basis for Processing Under GDPR: Legal Obligation

A

Legal Obligation:
Processing is required to comply with a legal obligation.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Lawful Basis for Processing Under GDPR: Legitimate Interest

A

Legitimate Interest:
Processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Lawful Basis for Processing Under GDPR: Contract

A

Contract:
Processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Lawful Basis for Processing Under GDPR: Vital Interests

A

Vital Interests:
Processing is necessary in order to protect the vital interests of the data subject or of another natural person.

17
Q

Lawful Basis for Processing Under GDPR Acronym

A

it doesn’t really make sense just sounds easy to say so easy to remember
Public Interest
Consent
Legal Obligation
Legitimate Interest
Contract
Vital Interests

18
Q

GDPR acryonm

A

PALADIN

P: Purpose Limitation
A: Accountability
L: Lawfulness, Fairness, and Transparency
A: Accuracy
D: Data Minimisation
I: Integrity and Confidentiality
N: (No excess storage) Storage Limitation