Data Protection & GDPR Flashcards
(12 cards)
What is the maximum fine under GDPR?
The larger of:
4% of worldwide turnover
£17.5mil
when a firm starts to process personal data, what must they do?
Inform the ICO
What kind of data does GDPR apply to?
“Personal Data”
What is personal data
Data that identifies an identifiable person
What are the 6 legal bases that exist for processing personal data?
1) Contractual
2) Consent
3) Legal Obligation
4) Vital Interest
5) Public Task
6) Legitimate Interest
There are 5 things that define the scope / treatment of client data, list them
1) Process Lawfully
2) Must be collected for specific purpose
3) Adequate, relevant & necessary
4) Kept for no longer than is necessary
5) Ensure security of data
6) Processed in a legal and transparent way
Give an example of a reason data would be collected due to: Consent
Client agrees to a newsletter sign up
Give an example of a reason data would be collected due to: Contract
Customer purchases online order to be delivered
Give an example of a reason data would be collected due to: Vital Interest
Medical professionals sharing patient data
Give an example of a reason data would be collected due to: Legitimate Interest
Protecting data security / preventing fraud
Give an example of a reason data would be collected due to: Public Task
Local authority managing voter registrations
Give an example of a reason data would be collected due to: Legal
Employee tax records for renumeration