What is Personal Data?
Information that can be used to identify someone
What is GDPR?
General Data Protection Regulation, or UK GDPR (Data Protection Act 2018)
What is a data subject?
Person the data relates to.
What is a data controller?
A person or business that decides how personal data is collected and determines what information is needed and why.
What is a data processor?
A business or sole trader that handles data and personal information on the instructions of another party.
What is the Information Commissioner’s Office?
What are the senior management team (SMT), directors, and councillors responsible for in FG?
They authorise the publication of policies, procedures and annual training for all staff on compliance issues
What is your line manager responsible for?
Overseeing how personal data is handled within the department.
Who has a responsibility within your firm for protecting data?
Everyone has a collective responsibility.
What is data minimisation?
Data should be adequate, relevant and limited to what is necessary, in relation to the purposes for which it is processed.
How long should data be stored?
6 - 15 years
What is a privacy notice?
explains their information rights.
What is erasure?
“the right to be forgotten”, the right to the erasure of records means that, in certain circumstances, and if the request is reasonable, people can approach organisations and ask the organisation to remove the information they have on them.
What is portability?
What is Object to Processing ?
What does it mean to Restrict processing?
You have the right to restrict an organisation’s data processing procedure when it comes to your own personal data.
What is a “Subject Access Request”?
SAR
- A request to see any records that relate to them.
Process - discuss with party what information they require before formal response.
1 CALENDAR MONTH TO RESPOND TO A FORMAL SAR.
What is a freedom of information request?
The Freedom of Information Act 2000
How do you respond to a FOI?
What is information security?
The protection from a loss of confidentiality, integrity and availability.
What are the GDPR Rights?
Process for a data breach?
What is FGs Data Protection Policy?
What are the penalties?
Maximum fine of £17.5 million or 4% of annual global turnover.