Data Protection Flashcards

1
Q

What constitutes personal data?

A

Any data relating to a natural person which can be used to directly or indirectly identify them

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is the maximum penalty for a breach of the Data Protection Act / GDPR?

A

4% of global turnover or £17.5m

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are the three key categories of people under GDPR?

A

Controller - the entity responsible for determining the purpose and means of processing personal data.

Note - can also be a joint controller - i.e. an RICS Regulated managing agent with leaseholders information is bound by the RICS Professional Regulations and so is a joint controller.

Processor - an entity with responsibility for processing personal data under instruction from the Controller.

Data processors do not have the same level of GDPR compliance responsibilities as controllers.

Controllers have the strictest level of responsibility for GDPR. Note - employees are treated as agents for the controller.

Data Protection Officer - internal person required within public authorities or organisations who regularly process data, or sensitive data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly