Data Management Flashcards

(18 cards)

1
Q

How do you demonstrate Accountability in terms of data protection

A

demonstrate compliance with data protection laws.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is the right to erasure?

A

The right for individuals to request deletion of their personal data under certain conditions.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

List some of the principles of data processing under the Act.

A

Data must be processed lawfully, fairly, and transparently.
Data minimisation
Storage limitation
Purpose limitation
Accuracy
Accountability
Security (integrity and confidentiality)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are the 8 rights under DPA 2018

A

Access
Objection
Rectification
Automated decision making.
Informed of datas existence
Data Portability
Erasure
Restrict Processing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Rights under Freedom of Information act.

A

Right to Access
Right to Information
Right to confirmation
No justification needed for request
Public access
Right to review

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Time frames for FOI request

A

20 working days

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is your understanding of confidentiality

A

Information that can only be shared with permission.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is meta data?

A

Data embedded within documents or photos. Need to be aware of meta data when sharing documents.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Benefits of cloud based storage

A

Backed up on encrypted servers
Accessibility is managed via online settings
Environmentally friendly.
Synchronous documents

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Information barrier - how would this work in practice?

A

Make client aware of risks
Keep a physical and digital barrier between two teams..
Secure document storage

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Key persons in GDPR?

A

Data Controller - determines means of processing personal data. Employer
Data Processor - person that processes personal data. Eg. Call centre
Data Protection Officer - Leadership role. Responsible for overseeing approach strategy and implementation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is in Section 10 of CRCA 2005?

A

Valuation Services: An officer of Revenue and Customs may provide a valuation of property under this section for HMRC purposes, or at the request of a public authority.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What does CRCA stand for

A

Commissioners for Revenue and Customs Act (2005)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What Sections of CRCA are important for VOA

A

Sec 10 - defines specific roles and functions of VO
Sec 17 - info for one function can be used for another VOA function.
Most important Sec 18 - confidentiality except for disclosure when performing statutory functions, for criminal investigation or when permission given
Sec 19 - wrongful disclosure is punishable by jail.
Sec 23 - with hold identifiable info.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Who would you report a breach of DPA to? And how long do you have to do it.

A

To IOC. Information Commissioners Office within 72 hours

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

The VO asks for data from Ratepayers on FORs. What is their authority to do this.

A

Under Sched 9 of 1988 LGFA the VO can request information that they reasonably believe will assist them.

17
Q

Explain the Right in DPA around automated decision making

A

Right to have a human review decision.

18
Q

What is a Subject Access Request

A

Under the Data Protection Act 2018 (DPA 2018) and UK GDPR, individuals have the right to request a copy of their personal data from organizations (a Subject Access Request or SAR). Organizations must respond within one month, free of charge, and provide data securely. The DPA 2018 ensures you can ask for data to be confirmed, accessed, and corrected.