What two articles of the GDPR codify the accountability principle?
Recital 75 of the GDPR lists what 8 examples of high-risk processing that require greater measures to protect against risk?
What 3 areas should a data controller consider when trying to establish appropriate data protection policies?
What is at the core for data controller’s compliance with the GDPR?
An internal data protection policy which outlines the basic contours of the measures to take in the processing and handling of personal data.
What are 6 key aspects to a data controller’s internal data protection policy?
The scope of an internal protection policy should include what?
A brief statement that explains both to whom the internal policy applies and type of processing activities it covers.
What 3 things should the policy statement of an internal protection policy include?
What 7 employee responsibilities should be listed in an internal data protection policy?
What are the 3 management responsibilities that should be included in a company’s internal data protection policy?
What are the 4 reporting incident requirements that should be included in a company’s internal data protection policy?
What 6 categories of info should be included in company’s internal data protection plan?
A companies internal allocation of its data protection responsibilities should facilitate what 3 things?
The concept of data privacy by design and default addresses what?
More broadly addresses the legal obligations set out by the GDPR and includes an ethical dimension.
What is the main design objective of Article 25 of the GDPR?
The main design objective is the effective implementation of the privacy principles and protection of the rights of data subjects into the appropriate measures of the processing.
What are 4 factors companies should take into account when implementing appropriate technical and organizational measures under Article 25 of the GDPR?
What are 3 types of technical measures that can be taken under Article 25 of the GDPR?
To ensure compliance with Article 25 of the GDPR, companies should carefully review and asses their data processing systems to determine what 6 things?
Article 30 of the GDPR outlines the records that must be kept by whom?
Under Article 30 of the GDPR, data controllers are required to keep records of what 7 types of info?
Under Article 30 of the GDPR, data processors are required to keep records of what 5 types of info?
The GDPR applies an exemption to its record keeping requirements if companies meet what 5 criteria?
What is another name for data protection impact assessments (DPIAs)?
Privacy impact assessments (PIAs)
What are DPIAs?
The process by which companies can systematically
1. Assess and identify the privacy and data protection impacts of any products they offer and services they provide, and
2. Take appropriate actions to prevent or at least minimize the risk of those impacts
What 3 questions should a company ask when determining whether a DPIA is necessary and how it should be carried out?