Data Management Flashcards
(14 cards)
What legislation governs data management?
Data Protection Act 2018
What are the 2 types of data?
Sensitive and personal
What are the 7 key principles of data management
- Lawfulness and transparency
- Accuracy
- Purpose limitation
- Accountability
- Integrity and confidentiality
- Data minimisation
- Storage limitation
What is GDPR?
General Data Protection Regulation
Governs how the personal data of individuals may be processed and transferred
Does GDPR still apply to the UK?
It is retained in our domestic law as the UK GDPR, but the UK has the independence to keep the framework under review.
The UK GDPR sits alongside an amended version of the DPA 2018
What does ISO 9001 govern?
International Standard for Quality Management Accreditation
FYI – helps organisations improve their processes and systems to meet customer needs and deliver high-quality products and services.
What does ISO14001 govern?
International standard for Environmental Management Accreditation
FYI – provides a framework for businesses to identify, monitor, and minimize their environmental impact by managing aspects like waste, resource usage, and compliance with relevant environmental laws
What does ISO27001 govern?
International Standard for Data Security Accreditation
FYI - governs how organizations manage the security of their information. It’s designed to help organizations protect financial information, intellectual property, employee details, and other assets
What do you do if there is a data breach?
Inform the data controller immediately on how the leak happened and what was shared
Who are the people involved in managing data?
- Data protection officer
Responsible for ensuring compliance - Data Controller
Determines purposes and meaning of possessing data - Data processor
Responsible for processing data on behalf of controller
What happens if DPA is breached?
Greatest of fine up to of £17.5mil or 4% of annual turnover
You sent an email by mistake to a friend, which included confidential client information and contact details. What do you do?
Inform the data controller immediately of the possible breach and the data shared
Practical steps to limit data breaches
- Password protected spreadsheets
- PDFs through mimecast, these require a 1 time password
- Timers on emails so that you have the opportunity to review you emails being sent
When do you need to have a Data Protection Officer?
When the firm has over 250 employees