How can data be kept secure?
Technologies:
- Disk encryption
- Regular backups off site
- Password protection
- Use of anti-virus protection
- Firewalls
What is Copyright?
A set of exclusive rights granted to the author and creator of original work
- These rights can be licenced, assigned and transferred
- Must acknowledge copy right for any information duplicated
What is crown copyright? Can you provide an example?
Relates to information produced by the government i.e laws, OS maps
What is GDPR?
General Data Protection Regulations
What is the Data Protection Act 2018?
What is the aim of the Data Protection Act 2018?
What are the fines for breach of these the data protection act?
What are the key requirements of UK GDPR and the Data Protection Act?
I.R.D.D.B
What would you do if there was a serious data breach at Mileway?
Report to ICO within 72 hours where there is a loss of personal data and a risk of harm to individuals
What rights are granted under GDPR? (IARERDOA)
What is the Freedom of Information Act 2000?
Gives individuals the right of access to information held by public bodies.
- The public body must give any individual requesting information whether it holds it
- Required to supply within 20 working days of request
- Can charge for the provision of information
What exemptions to the Freedom of Information Act 2000 are offered?
What is a data controller?
Someone who decides how and why personal data is processed and is directly responsible for GDPR
- Under Article 5(2)
What is Mileway’s data policy?
In line with the GDPR regs and found on our website
States that:
- People have rights to withdraw consent or ‘opt-out’ of marketing
- Right of access, rectification and erasure
- Data portability
- Right to restriction of processing
What are the principles of GDPR?
LPD ASIA
Article 5(1) princles:
7 keys principles:
- Lawfulness, fairness and transparency
- Purpose limitation
- Data minimisation
- Accuracy
- Storage limitation
- Integrity and confidentiality (security)
- Accountability
Under Article 5(2) requires that a data controller “shall be responsible for compliance with the principles”