What are the principles set out in Article 5 of the UK GDPR 2020?
LS MAPS
Lawful
Securely Processed
Data Minimisation
Accurate
Purpose Limitation
Storage Limitation
Article 5:
Processed lawfully, fairly, and in a transparent manner.
Collected for specified, explicit, and legitimate purposes.
Adequate, relevant, and limited to necessity.
Accurate and Up-to-Date.
Kept in a form that permits identification for no longer than is necessary.
Processed in a way that ensures appropriate security.
Data controller will be responsible for, and can evidence, compliance with the principles.
What is the purpose of UK GDPR?
When should a data breach be reported?
Personal data breaches must be reported to the ICO within 72 hours.
What is the ICO?
Information Commissioners Office
What is the maximum fine for a data breach?
Up to 4% of Global Turnover OR £17.5M
What are examples of data security measures?
Explain how your data storage system keeps data secure.
What is a data controller?
Determines the purposes and means of processing personal data.
Can be alone or joint role.
What is a data processor?
Processes the personal data on behalf of the data controller.
What legislation is relevant to data management?
Data Protection Act 2018
What are the individual rights under UK GDPR?
What is the Freedom of Information Act 2000?
Right for individuals to access information held by the public sector.
What are the exemptions of an FOI Request?
Request must be in writing.
How many days must a response by provided in for a FOI Request?
20 working days.
What is personal data?
Anything that identifies a person i.e., name, gender, location data, cultural, social, economic related to an individual.
What are the benefits of a cloud-based storage system?
What is the meaning of a non-disclosure agreement?
If two separate departments within your firm were working for rival companies, how would you ensure client sensitive data was managed?
Who are the key persons outlined within GDPR?
Data Controller - natural person or legal entity that determines the purposes and means of the processing of personal data.
Data Processor - processes personal data on behalf of the controller.
What things must companies put in place to ensure GDPR compliance?
How is data managed and protected in your firm?