All data sources need to be what?
Verified
Accurate
Up to date
Reliable
What are the five principles of better regulation?
The five principles are:
1. Proportionality
2. Accountability
3. Consistency
4. Transparency
5. Targeting
PACTT
What regulation governs laws on data protection and privacy?
UK General Data Protection Regulation 2020
What is the DPA 2018?
Data Protection Act 2018 (replaced DPA 1998)
Controls how personal information is used by organisations, businesses or government
Designed to protect personally identifiable information
UKs implementation of General Data Protection Regulations (GDPR)
DPA - What are the key principles of DPA 2018?
The act ensures that data is:
DPA - Tell me about DPA 2018?
Controls how your personal information is used by organisations, businesses or the government
Everyone responsible for using personal data has to follow strict rules called ‘Data Protection Principles’ also known as PACKAP
Consumer rights (ACCEP)
DPA - Tell me about the 7 principles of DPA?
Information held must be:
DPA - Who has to comply with DPA principles?
Everyone responsible for using personal data
DPA - What are a persons rights under the DPA 2018?
People have the right to:
1. To be informed about how their data is being used
2. The right to access their data
3. The right to have incorrect information updated
4. To have their data erased
5. To stop or restrict the processing of their data
6. The right of portability
7. To object to the use of their data
8. Right to automated decision making and profiling
Tell me about GDPR?
Following Brexit, the UK GDPR 2020 was introduced (General Data Protection Regulation)
This sets out the main responsibilities for organisations using, storing and handling personal data
Article 5 sets out consumer rights
GDPR - What are the GDPR consumer rights?
A - access
C - consent
C - correction
E - erasure
P - data portability
GDPR - What are the 7 principles of GDPR?
GDPR - What are the 8 individual rights under GDPR?
GDPR - What role must firms have under GDPR?
Data Protection Officer - Role exists within companies that process the personal data of EU citizens
GDPR - How does GDPR apply to the VOA?
The right to correct is something we actively do in the Check stage and in the FOR where personal data is explicitly collected
GDPR - Who are the key persons outlined within GDPR?
Controller - person that determines the purpose and means of processing personal data e.g. employer
Processor - person that processes personal data on behalf of the controller e.g. call centres acting on behalf of its client
Data Protection Officer - leadership role required by EU GDPR (responsible for overseeing data protection approach, strategy and implementation)
GDPR - What should companies put in place to ensure GDPR compliance?
Raise awareness across the business
Audit personal data
Review procedures supporting individual rights
Identify and document the legal basis for processing personal data under GDPR
Train staff and give them the information
GDPR - What are the 3 principles of GDPR and DPA 2018?
GDPR - Exemptions?
Domestic use
Law enforcement
Intelligent services
How do you comply with UKGDPR and DPA 2018 in your role?
I am aware of different types of information we hold
I complete relevant training on understanding UK GDPR and DPA
I store data in the appropriate locations
I use appropriate document markings when storing and sharing information (official-sensitive)
I use secure information sharing i.e. outlook rather than teams
What is the max GDPR fine set by UK GDPR and DPA 2018?
£20m euros (£17.5m) or 4% of annual global turnover (whichever is highest)
Could also face criminal charges
How are DPA and GDPR different?
GDPR relates to personal data whereas data protection relates to all data
What is the Freedom of Information Act 2000?
Gives individuals the right of access to information held by public bodies
The public body must tell any individuals requesting sight of the information whether it holds that information
Must be supplied within 20 working days in the format required
Can be charged for the provision of the information
FOI - What is essential to understand regarding the Freedom of Information Act 2000?
It is essential to understand the rights of individuals to request the information which we hold on them.