What are the 6 principles of GDPR? Flashcards
Lawfulness, fairness and transparency
Organisations should only process personal data lawfully and in a fair way. People must be told very clearly what the organisation intends to do with the personal data collected.
Purpose Limitation
Personal data should be collected for specific, explicit and legitimate purposes, which is clearly told to the data subject. The personal data cannot be used for any other purpose.
Data Minimisation
Personal data should be adequate, relevant and limited to what is needed.
Accuracy
Personal data must be accurate, and where necessary, kept up to date. Reasonable steps should be taken to rectify any data that is found to be inaccurate.
Storage Limitation
Personal data should not be kept for any longer than is necessary for the purpose it was collected for. When not needed it must be disposed of securely.
Integrity and Confidentiality
Personal data must be protected against unauthorised access, accidental loss, destruction or damage. Both physical and technical controls should be used as appropiate.