What is the main concern of using / transferring data across international borders?
The legislation around data handling may be more stringent in one of the two countries and organisations need to take extra care to not breach local standards.
List the eight conditions of the POPI Act in South Africa.
Describe the POPI Act condition of accountability.
The party responsible for processing the data is also responsible for compliance with POPI.
Describe the POPI Act condition of processing limitation.
Information must be processed in a fair, lawful and relevant manner, after consent is given by the data subject.
Describe the POPI Act condition of purpose specification.
Personal information must be collected for a specific purpose. Record keeping to be destroyed when personal data is no longer relevant or authorised to be held.
Describe the POPI Act condition of further processing limitation
Further processing must be compatible with the initial collection prupose.
Describe the POPI Act condition of information quality
Data completeness, accuracy and updates to be ensured by holder of the data.
Describe the POPI Act condition of openness
Documentation to be maintained on all processing operations and maintaining transparency on data use.
Describe the POPI Act condition of security safegaurds
Integrity and confidentiality of personal data must be secured and all processing done only by authorised operators. Notification to be done on security compromises.
Describe the POPI Act condition of data subject participation.
The data subject may request confirmation of personal data held and request correction or deletion of any inaccurate, misleading or outdated information held.
Aside from criminal action and fines, what is another damaging effect of data breaches occurring within a company’s data bases?
Damage to reputation and the ability to retain and attract clients.
Give the aspects that a data governance policy should aim to cover.
Give the data governance risks.
Give a data concern around mergers and acquisitions.
Give the main risks associated with risks.
Why may past data not be an accurate reflection of future experience.
State the data protection principle which it can be difficult to meet when using big data
Personal data should be adequate, relevant and not excessive for the purposes concerned.
How can companies avoid big data being excessive for the given purpose?
Anonymisation can be used to ensure that the data is not considered to be personal data.
List the main uses that actuaries make of data.
List the key data required for active members when valuing a pension scheme
Outline the design features of a good proposal form.
Give a design feature of the claims form in order to store good quality data.
Should be clear and unambiguous and link to the proposal form - to cross check information
Give features of data inputting processes that can ensure that good quality data is stored by a company.
Give the data system features that can help ensure that good quality data is stored by an insurance company.