What is the primary purpose of the Data Protection Act (1998)?
To protect the privacy of individuals by ensuring that their personal information is processed in an ethical manner.
What significant law replaced the Data Protection Act (1998) in the EU?
General Data Protection Regulations (GDPR) enforced on May 25, 2018.
What is the maximum fine for breaching GDPR?
€20 million or 4% of a business’s annual turnover, whichever is largest.
What body is responsible for investigating data protection violations in the UK?
Information Commissioners Office (ICO).
Fill in the blank: The Data Protection Act (1998) covers data stored on _______.
paper and audio data.
What principle was added to the GDPR that was not in the Data Protection Act (1998)?
Accountability principle.
What does the Computer Misuse Act (1990) protect users against?
Theft and damage of information stored using IT systems.
What is the punishment for unauthorized access to computer material under the Computer Misuse Act?
Up to 2 years in prison and/or a large fine.
True or False: The Computer Misuse Act (1990) only applies to successful hacking attempts.
False.
What additional offence was added by the Police and Justice Act (2006)?
Making, supplying or obtaining anything which can be used in computer misuse offences.
What does the Telecommunications (Lawful Business Practice) (Interception of Communications) Regulations (2000) allow organizations to do?
Monitor communications over their network.
List one of the purposes for which organizations can monitor communications under the Telecommunications Regulations.
What three classes of fraud are defined in the Fraud Act (2006)?
What is the maximum punishment for fraud under the Fraud Act (2006)?
Up to 10 years imprisonment.
What does the Health and Safety at Work Act (1974) require employers to do?
Perform a risk assessment and ensure the health, safety, and welfare of employees.
What is one duty of employees under the Health and Safety at Work Act?
Take care of their own health & safety and that of others.
What can the Health & Safety Executive do if a business is found guilty of an HSWA offence?
Impose an unlimited fine and/or a prison term of up to 2 years.
Fill in the blank: The Health & Safety at Work Act is enforced by the _______.
Health & Safety Executive (HSE).
What happened to the punishment for unauthorized access under the Police and Justice Act (2006)?
Increased to 2 years imprisonment.
What is the consequence of breaching the Data Protection Act (1998)?
A fine of up to £500,000.
What is a key feature of the accountability principle under GDPR?
Organizations must have appropriate measures and records to demonstrate compliance.
True or False: The Computer Misuse Act (1990) only applies to traditional hacking.
False.