Week 10 Flashcards
(12 cards)
What law governs data protection in the UK after Brexit?
UK GDPR and Data Protection Act (DPA) 2018.
Who is a Data Controller?
The person or organization that decides how and why personal data is used.
Who is a Data Processor?
A person or company that processes data on behalf of the controller.
Name the 7 principles of UK GDPR (Article 5).
Lawfulness, fairness, transparency
Purpose limitation
Data minimisation
Accuracy
Storage limitation
Integrity and confidentiality
Accountability
What are the 6 lawful bases for processing personal data (Article 6)?
Consent
Contract
Legal obligation
Vital interests
Public task
Legitimate interests
What is Special Category Data?
Sensitive data like health, race, religion, sexual orientation — needs stronger protection.
Name five rights of a data subject under UK GDPR.
Any of:
- Right to be informed – Know how their data is used.
- Right of access – See their data.
- Right to rectification – Fix incorrect data.
- Right to erasure – “Right to be forgotten.”
- Right to restrict processing – Limit how it’s used.
- Right to data portability – Transfer data to another service.
- Right to object – Say no to data use in some cases.
- Rights in automated decision-making – Protection from decisions made solely by computers.
What is a Data Protection Impact Assessment (DPIA)?
A process to identify and reduce data protection risks in new projects.
When is a DPIA required?
You need a DPIA when your project might put people’s privacy at high risk. This includes:
When using new tech
Tracking people
Watching people regularly
Handling sensitive data on a large scale e.g. health
What are the key steps in a DPIA?
Describe the processing
Assess the necessity and proportionality
Identify and assess risks
Define ways to reduce those risks
Why is DPIA important?
It helps organizations comply with the law, protect people’s privacy, and avoid fines.
What can happen if a company doesn’t comply with GDPR?
Heavy fines (up to £17.5 million or 4% of global turnover), legal action, reputational damage.