Data Management Flashcards

(9 cards)

1
Q

What legislation for Data Management

A

UK: Data Protection Act 2018!
EU: GDPR (General Data Protection Regulations)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What do you need to consider when handling data?

A

Is the data:
- Lawful
- Fair
- Accurate
- Transparent
- Secure

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What things do you do to ensure safe data handling ?

A
  • Only keep relevant data
  • Do not keep data for longer than needed.
  • Keep on secure servers
  • Report breaches promptly
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What actions improve data protection daily at work?

A
  • Elearning, CPD and Seminars
  • Strong passwords
  • Locked filing cabinets
  • Secure servers
  • Clear desk policy
  • Erase old data
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are the 7 key principles of Data Management (or GDPR)?

A
  1. Lawful, Fair Transparent
  2. Purpose limitation
  3. Data Minimisation
  4. Accuracy
  5. Storage limitation
  6. Integrity and Confidentiality
  7. Accountability
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What 2 types of data are you aware of?

Give examples for both

A

Sensitive data (Age, Race, Religion - 9 protected characteristics)

Personal Data (Address, email, phone)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What are people’s rights relating to their data under GPRD Data Protection Act?

A

Right to…
- request a copy of the data held.
- erasure.
- know how data is being used.
- restrict processing .
- rectify inaccurate data.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is ISO 27001?

What does ISO Stand for?

A

Information Security Management

International Organisation for Standardisation

Why:
- Data Protection systems
- Cyber security
- Client confidentiality

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

If you were responsible for a data breach, who would you notify and what is the procedure?

A

Notify - Data Protection Officer (or Risk and Compliance team at FG)

  1. Contact party who has been sent incorrect data and ask them to delete and not share.
  2. Notify Data protection officer
  3. Notify Client
How well did you know this?
1
Not at all
2
3
4
5
Perfectly