Data Science and Law Module 4 Part 1

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/32

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 11:15 AM on 6/29/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

33 Terms

1
New cards

Right to Privacy

Right to be let alone is conceived as the freedom from any unauthorized intrusion or interference by public and private bodies into private life

2
New cards

Right to data protection

It is based on the concept of personal data, requires that the (authorized) use of the same by private and public bodies is made in accordance with specific legal standards

3
New cards

Treaty on the Functioning of the EU (TFEU)

Everyone has the right to the protection of personal data concerning them (Art. 16)

4
New cards

Charter of the Fundamental Rights of the EU (CFREU)

Respect for private and family life (Art. 7) and Protection of personal data (Art. 8)

5
New cards

General Data Protection Regulation (GDPR)

EU Standard that gives EU citizens control over data and their privacy

6
New cards

Scope of GDPR Application

applies to the processing of personal data wholly or partly by automated means and to the processing other than by automated means of personal data which form part of a filing system or are intended to form part of a filing system

7
New cards

Processing of personal data

any operation or set of operations which is performed on personal data

8
New cards

Personal Data

any information relating to an identified or identifiable natural person (‘data subject’)

9
New cards

Identified vs Identifiable

Identified: Person is distinguishable from others

Identifiable: Not identified, possible to do so

10
New cards

Possible identifiers

name, an identification number; location data; age; any factor specific to the physical, physiological, genetic, mental, economic, cultural, or social identity

11
New cards

Psuedonymization

processing of personal data in such a way that this data can no longer be attributed to a specific individual, without the use of additional information

12
New cards

GDPR Exceptions

Areas outside EU law, national security, personal household use, law enforcement and criminal justice

13
New cards

Territorial Scope

Concerns processing of data for commercial and behavioral purposes within EU territory, regardless of where the controller/processor has their operations in

14
New cards

Controller

The natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data

15
New cards

Processor

natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller;

16
New cards

Other Actors in Data Protection Law

Data Protection Officers (DPO), Data Protection Authorities

17
New cards

Data Protection Officers

independent security and legal expert responsible for overseeing an organization's data protection strategy and ensuring compliance with privacy laws like the GDPR.

18
New cards

Data Protection Authorities

independent public watchdog established by a government to monitor and enforce privacy laws

19
New cards

Data Protection Principles

Lawfulness, Fairness and Transparency - Purpose Limitation - Storage Limitation - Data Minimization - Accuracy - Integrity and Confidentiality - Accountability

20
New cards

Lawfulness

a legal ground is required to justify the processing of personal data

21
New cards

Transparency

data subjects need to be informed about how their personal data are processed in clear and simple language - so they need to understand how their data are being used by the data controller

22
New cards

Fairness

personal data must be processed in a transparent and even ethical manner

23
New cards

Purpose Limitation

Data controllers must determine, in advance of any processing, why they want to process certain personal data, purpose chosen needs to be specific and clear so that data subjects know what to expect. Personal data shall not be further processed in a manner that is

incompatible with those purposes

24
New cards

Data Minimization

personal data shall be adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed

25
New cards

Accuracy

Data controllers must make sure that the personal data they process are

accurate and up to date. Data that is inaccurate, having regard to the purposes of the processing, is erased or rectified without delay

26
New cards

Storage Limitation

Data controllers need to establish time limits for keeping the data and erasing them permanently when they are no longer necessary (data retention)

27
New cards

Integrity and Confidentiality

Data controllers need to make sure that the processing of personal data ensures adequate security, by putting in place technical and organizational measures

28
New cards

Integrity and Confidentiality: Technical Measures

encryption, pseudonymization

29
New cards

Integrity and Confidentiality: Organizational measures

placing personal data copies in a locked room inside the office building, only giving permissions to access the data to certain employees that need it to carry out their tasks

30
New cards

What happens if data is breached?

It must be notified to the Supervisory Authority in 72 hours. If the breach is likely to result in a high risk to the rights and freedoms of natural persons, data subjects must also be communicated to the data subjects

31
New cards

Accountability

Data controllers are responsible for compliance with data protection law rules and must be able to demonstrate compliance

32
New cards

How can compliance be demonstrated?

maintaining a record of all processing activities the company carries out. if relying on consent, must demonstrate valid consent has been obtained; if relying on legitimate interest, must demonstrate balancing exercise was carried out, etc

33
New cards

Risk-based approach

required level of data security must be identified on a case-by-case basis through an objective risk assessment. GDPR encourages controllers to engage in risk analysis and to adopt risk-measured responses, to account for possible scenarios.