Data Management Flashcards
(37 cards)
What Is data management?
Data management is the practice of collecting, organising, protecting, and storing an organisations data so that it can be analysed for decision making purposes.
What does GDPR mean?
General Data Protection Regulations
What are the General Data Protection Regulations?
A law that was created in the EU to protect the personal data of citizens, by telling companies what they can and can’t do with personal data, and to use it correctly and lawfully.
When did GDPR come into force?
25th May 2018
What changes did GDPR bring?
Definition of data
Breaches have to be reported in 72 hours
Larger fines introduced - €20 million or 4% annual global turnover
Data protection officer for companies with 250+ employees or 5000+ subject profiles annually.
What is personal data?
Data which can identify someone: names, phone number, email address or ID number.
What is special category data?
Type of personal data seen as particularly sensitive.
Includes: race, religion, genetic data, disability, marital status and biometric data.
Special categories are outlined under Article 9 of GDPR stating you must have a lawful basis to collect special category data.
How to report a data breach?
Within 72 hours report to the information commissioner office.
Information commissioner office is a third-party organisation that upholds rights for the public who will investigate potential complaints for breaches of GDPR or DPA.
What is a data controller?
The party that determines the purposes of processing data and how and why this is done (often the company).
What is a data processor?
Someone who processes data on behalf of the data controller.
What is a data subject?
A data subject is the party that the data can identify.
How would you get rid of data?
Paper copy - place in appropriate bin (confidential was blue bin).
Online: redacted - delete from all areas.
What is data purpose under GDPR?
Organisations must clearly inform individuals of purposes for which data is processed.
Data held must have a specified purpose and must not be processed for incompatible purposes.
What are the restrictions around consent under GDPR?
It must be freely given without coercion
Specific consent for specific data
Consent must be given after being informed of use of collected data and processing.
What is Data Protection Act 2018?
The UK equivalent/interpretation of GDPR - everyone follows data protection principles while using personal data.
Add on to the Data Protection Act 1968 introducing: larger fines, requirement to report in 72 hours, definition of data change for new technology, required 250+ person company to have a data protection officer.
What are the 7 principles of GDPR?
Lawfulness, Accuracy, Purpose limitation, Data minimisation, Accountability, Storage limitation, Security.
What is the punishment for breach of GDPR?
Fine up to €20 million or 4% annual global turnover.
What is information governance?
Framework governing how information is handled ensuring it is done correctly and lawfully.
Organisations must have processes in place for reporting and recording data security breaches and provide training to staff.
What is the Freedom of Information Act 2000?
Provide public access to information held by public authorities.
It covers all information held: emails, notes, recordings of phone calls, CCTV.
Requests can be refused if has potential to cause unjustified disruption.
How to request information? (FOI)
Request must be made in writing including name, contact address and what information you are after.
Organisations have 20 working days to respond and must establish identity before giving out personal data.
What is Section 10 of FOI?
Specifies that as a public authority you have 20 working days to respond to a request.
What is Section 14 of FOI?
Protects public authorities by allowing the refusal of requests if they have potential to cause an unjust level of disruption, irritation or distress.
What is a subject access request?
This allows you to request the personal information a company holds about you.
Must submit written requrest with clear proof of identity and what information you are requesting.
How does your organisation keep data secure?
Fire walls, virus protection
Spyware detection
Systems we use have certain location for different types of information
Training for staff