What are the main acts relating to Data Protection?
Data Protection Act 2018 and the UK general data protection regulations 2017
What does the Data Protection Act 2018 do?
Creates a single data protection regime which gives individuals powers to control how third parties use their data
What are the 8 rights under the DPA?
What is article 5 of the GDPR?
Sets out main principles of GDPR
What are the principles of article 5?
What are the key points of the Data Protection Act 2018?
What are the timeframes involved if there is a breach?
72 hours must report to ICO. Must report to client asap.
What are the fines involved with not complying with GDPR?
4% global turnover or £17.5 million, whichever is the higher
Explain to me your freedom of information request situation?
Working for a private client, so it wasn’t technically a Freedom Of Information request because it wasn’t a public body. The phrase that was used.
Under Data Protection Act, I understand that you must respond within one calendar month (with the possibility to extend for 2 months if the request is complex).
For freedom of information requests under the freedom of information act 2000, public bodies must respond within 20 working days.
My firm aimed to respond within the 20 working days, although they didn’t need to in this case and could have taken a calendar month.
When can you turn down a freedom of information request?
When it is contrary to GDPR or it would prejudice criminal matters or a person/companies commercial interest.
What are some types of security to protect data?