Rights of Individuals regarding their own Information and Data Flashcards
10.1 Key Requirements of Legislation Relating of the Security of Information and Data (10 cards)
What are the rights of access (‘right to ask’) relating to an individual’s info and data under the GDPR?
Individuals can ask an organisation or business for copies of their personal data being held.
This is known as a subject access request (SAR)
What is a Subject Access Request (SAR)?
The right to ask a business for your personal data.
What are the rights to rectification relating to an individual’s info and data under the GDPR?
Individuals can request inaccurate data is corrected by an organisation of business, if incomplete, ask for additional detail to be added
What are the rights to erasure (‘right to be forgotten’) relating to an individual’s info and data under the GDPR?
An individual can ask an organisation or business that holds their personal data to be deleted
What are the rights to object relating to an individual’s info and data under the GDPR?
In certain circumstances, an individual can ask an organisation or business not to precess, or to stop processing their personal data.
What are the rights to be informed relating to an individual’s info and data under the GDPR?
An individual must be informed if an orgnaisation or business is using their personal data.
What are the rights to restriction relating to an individual’s info and data under the GDPR?
An individual can ask an organisation or business to restrict the use of their personal data or not to delete it.
What are the rights to data portability relating to an individual’s info and data under the GDPR?
An individual can ask an orgnaisation or business to transfer their personal data to another organisation or business, or to provide a copy to the personal data in a format that is accessible.
What is the Information Commissioners Office (ICO)?
The ICO is a body set up by the uk government, they can investigate claims, and take action aginst anyone who has misused personal data.
What are the consequences for the business if they do not handle data properly?
- Financial (e.g. fines)
- Legal
- Repuational
- Loss of business opportunities.