Data Management V2 Flashcards

(30 cards)

1
Q

What legislation covers data protection?

A

Data Protection Act 2018
UK GDPR

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is the purpose of the Data Protection Act 2018?

A

To bring UK GDPR into law following Brexit and give powers to a UK regulatory body.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is the data protection regulatory body in the UK?

A

Information Commissioners Office

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are the principles of the Data Protection Act 2018?

A

Lawfulness
Purpose Limitation
Data Minimisation
Accuracy
Accountability
Security
Storage Limitation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are the rights of the Data Protection Act 2018?

A

Right to Restrict Processing
Right to Access
Right to Data Portability
Right to be Informed
Right to Object
Right to Erasure
Right to Restrict Processing
Rights with regards to Automated Decision Making

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What are the three parties in the Data Protection Act 2018?

A

Data Subject
Data Controller
Data Processor

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is a Data Subject?

A

Someone who’s information is collected.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is a Data Controller?

A

Someone who decides what information is collected.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is a Data Processor?

A

Someone who handles data on behalf of the Data Controller.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is a subject access request and what is the timeline for this?

A

Request for information about yourself, must be processed within 30 days.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is a Freedom of Information request?

A

A request for information held by a public body. Must be processed within 20 working days.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What legislation covers FOI requests?

A

Freedom of Information Act 2000

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What information does not have to be provided in a FOI request?

A

Personal or sensitive information.
Information which is confidential or business sensitive.
Matters of national security.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is Personal Information and what is Sensitive Information?

A

Personal information is information which can be used to identify an individual.

Sensitive information is a subset of personal information requiring special care as it may cause harm i.e. medical records.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

How can you ensure that data is reliable?

A

Verify it through triangulating multiple sources.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What types of digital security do you use?

A

Encryption
Fire Walls
Discrete filing system
Multi-factor authentication

17
Q

What physical data security do you use?

A

Clear desk policy
Key card building access
Confidential waste bins

18
Q

What is copyright?

A

The exclusive right to intellectual property including licencing and the right to make copies.

19
Q

What is intellectual property?

A

An intangible asset which is a creation of the mind such as music.

20
Q

If a data breach occurs, what would you do?

A

Inform the Data Protection Officer.

21
Q

When must a Data Protection Officer inform the ICO of a data breach?

A

Within 72 hours.

22
Q

What is the penalty for breaching the Data Protection Act 2018?

A

A fine which is the greater of 4% of turnover of £17.5m

23
Q

What is the purpose of UK GDPR

A

To give individuals greater control over their own information and how it is recorded.

24
Q

What is a Privacy Notice?

A

A document provided to data subjects outlining what data is being collected, for what purpose and their rights.

25
What data security threats might you encounter?
Ransomware Phishing DDOS attack Insider threat - employee error Loss or theft of equipment Hacking
26
Open Storage Land, Stoke-on-Trent - Why did you password protect your spreadsheet?
It included information of enquiring parties, including names which is personal information under UK GDPR. The offers were also commercially sensitive.
27
Open Storage Land, Stoke-on-Trent - How did you advise the enquirers that you were collecting their information?
I requested permission via email when the enquiries were received and directed them to my firm's privacy notice.
28
Golborne Point - Why did you hold digital records instead of paper records?
Easier to store and organise. More secure.
29
Golborne Point - Why were the measurements / specifications of the unit treated so securely?
I have a duty to maintain the confidentiality of the instruction to my client and information gathered can be commercially sensitive. Tenant contact details is also personal information.
30
Golborne Point - Why did you delete the documentation from your phone?
Documents protected by password and VPN but are stored on the phone's internal storage which is not as secure as my firm's servers.