Chapter 13 - Data Protection Law Flashcards

1
Q

What does the Data protection act 2018 set out to do?

A

Uk approach to data protection

Embodies the principles and rights of EU GDPR

Sets out framework of rules wider than GDPR

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What do data controllers do?

A

Determine purpose and means of processing personal data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What do data processors do?

A

Responsible for processing personal data on behalf of controller

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are data subjects?

A

Identified/identifiable individuals to whom personal data relates

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Where does the Data protection act 2018 apply?

A

When personal data is held on computer based info systems/ manual files

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What does personal data cover?

A

Any info relatable to an individual

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is the role of the info commissioner?

A

Uk regulator for data protection

Statutory powers to enforce non-compliance

must be informed within 72 hours of a breach

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What are the punishments for a breach of data protection?

A

Fine of up to £17.5 mil or 4% of annual turnover, imposed by info commissioner

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What are the principles of data protection?

A

Lawfulness
Data minimisation
Purpose limitation
Accuracy
Storage limitation
Integrity and confidentiality

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What rights do data subjects have?

A

Be informed
Access
Rectification
Erasure
Restrict processing
Data portability
Object
Automated decision making and profiling

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What are the exemptions from the data protection act 2018?

A

Employers may process employee data without consent, acting within employment law

Academic institutions exempt from data processing rules if for academic reasons

Scientific and historical research organisations exempt where principles impair core activities

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Is the data controller obliged to take all necessary steps to ensure that data held about an individual is accurate?

A

No

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Does the data controller have to keep the data subject informed (and supply copies) of all personal data
held or processed in respect of that data subject?

A

No

How well did you know this?
1
Not at all
2
3
4
5
Perfectly