4.1 Uk legislation & regulation relating to storing and use of information Flashcards

(36 cards)

1
Q

What is the Data protection act/GDPR?

A

This act protects the data of individuals that is stored on computers and the processed by organisations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is a data subject?

A

each person who has their data stored

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

what is a data controller?

A

an employee within an organisation who are responsible for registering with the Information Commissioner

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is the Information Commissioner?

A

The person in the UK who is responsible for managing several laws (Daya Protection act)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is the 1st principle of the Data protection act?

A
  1. Data must be collected lawfully and processed fairly in a way that is clear to individuals
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is the 2nd principle of the Data protection act?

A
  1. Data must only be collected for specific reasons and not to be used for anything beyond that
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is the 3rd principle of the Data protection act?

A
  1. Data must be relevant and not excessive for the intended purpose.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is the 4th principle of the Data protection act?

A
  1. Accuracy – Data must be kept accurate and up to date, with mechanisms to correct or delete incorrect information.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is the 5th principle of the Data protection act?

A
  1. Data must not be kept no longer than necessary
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

what is the sixth principle of the data protection act?

A
  1. Data must be protected against unauthorized access, loss, or damage using appropriate security measures.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is one action an organisation must stick to when following the data protection act?

A

There must be strong security measures in practice to protect data from being accessed or transferred without unauthorisation.

This could be physical or digital security measures

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is another action an organisation must stick to when following the data protection act?

A

staff must be trained so that they are clearly aware of the responsibilities. For example. They should know that these can only be used for reasons specified when it is collected and should not be transmitted to others without permission from the data subject.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is another action an organisation must stick to when following the data protection act?

A

Data subjects have the right to make SAR and receive a copy of their data. Companies must accept this request by asking the data subject for identification verification I’m presenting the data to them securely.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is one right at the subject has?

A

The individual must verify their identity with valid ID

The organisation must provide the requested information within 40 days .

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is the computer misuse act?

A

Act attempts to punish those use computers inappropriately
Breaking these rules could lead to fines and persecution

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

what is the first principle of the computer misuse act?

A

No unauthorised access to data.

17
Q

What is the 2nd principle of the Computer misuse act?

A

No unauthored access to data that could be used for illegal crimes

18
Q

what is the 3rd principle of the Computer misuse act?

A

No unauthorised modification of data
E.g. Actions that damage, delete, alter, or disrupt computer systems, such as spreading viruses, malware, or launching denial-of-service (DoS) attacks.

19
Q

what is the regulation of investigaritory powers act 2000? (RIPA)

A

This act was introduced to monitor and access online communication of suspected criminals

20
Q

what can an Internet service provider do?

A
  • Must provide access to the suspects online communication such as emails/social media
  • ISPs could install surveillance software to track the suspects online activity.
21
Q

What is the Freedom in Information act 2000?

A

this act allows people to request public authorities to release information

22
Q

How should a Freedom of Information request be done?

A

Formally submitted in a letter or email with the reply from the organisation within 20 days

23
Q

What is the Copyright, Designs and Patents act 1988?

A

This act makes it a criminal offence to copy work that is not your work without permission from the owner

24
Q

what kind of owner do if their work has been copyrighted?

A

The owner can bring legal proceedings in court to someone who has stole their work

25
What does the Copright act prohibit?
- Making copies of copyrighted material to sell to others. • Importing and downloading illegally copied material (except for personal use). • Distributing enough copyrighted material to have a noticeable effect on the copyright holder. • Possessing equipment used to copy copyrighted material, as part of a business.
26
What is the Protection of Freedoms act 2012?
designed to protect civil liberties and personal privacy
27
What is the 1st part of the protection of freedoms act 2012
states how biometric data is stored, handled and collected. Immediate deletion if someone is arrested but not charged. • Deletion after 3 years if a person is charged but not convicted (unless extended by a judge). • Retention of data only for serious offenses like murder or terrorism.
28
What is 2nd part of this act?
Regulation for CCTV and ANPR The law introduced guidelines for how public bodies, such as councils and police, use: •CCTV (Closed-Circuit Television) – to prevent excessive surveillance of the public. •ANPR (Automatic Number Plate Recognition) – to ensure fair use of vehicle tracking systems.
29
what is the Privacy and electronic communications regulations Act 2003?
regulates how an organisation can communicate with individuals
30
What are the rules of this act?
It is an offence to directly contact an individual unless they have specifically opted in to receive communication This is commonly managed by using tick boxes on online stores where you must opt-in to receiving promotional material.
31
What is another rule?
Companies must clearly state who they are when contacting customers, such as displaying the phone number when calling - and not 'hiding' the number.
32
What is another rule?
Organisations must explain how cookies are used on their website.
33
what is the Information of Commissioners code of practice ?
The ICO publishes code of practices about a various data protection and privacy topics.
34
what is One code of practice?
how Organisations should share data
35
what is the Equality act 2010?
Legally protects people from discrimination in the workplace and in wider society
36
what is the aim of this act?
to end discrimination in the work place open up fair opportunities for every employee regardless of physical or behavioural characteristics that are outside of their control.