iDEA Inspiring Digital Enterprise Awards

GDPR Principles

The way you handle personal information must follow these 7 principles:

Transparency

Personal data must be processed in a lawful and transparent manner, ensuring fairness towards the individuals whose personal data you are processing.

1 1

Purpose Limitation

You must have specific reasons for processing the data and you must highlight those purposes to individuals when collecting their personal data. The act of simply collecting data for no purpose is no longer permitted.

2 2

Data Minimisation

You must only collect data related to fulfilling your specific reasons.

3 3

Accuracy

You must ensure the accuracy of the data, and directly relate that to your specific reasons.

4 4

Storage Limitation

The collected data should be stored for not longer than necessary to fulfil the purposes for which it was collected.

5 5

Integrity and Confidentiality

Appropriate technical and organisational safeguards must be in place to ensure the security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, damage or destruction.

6 6

Accountability

All organisations who process personal data must demonstrate compliance with each of the above Principles.

7 7

ABC Limited has been audited to see how compliant it is with GDPR regulations. Below are a few of the steps the company has been advised to take. Which of the GDPR principles do these steps meet?

Whoops - you got two wrong, you'll have to start again...

After gathering all information about the data that ABC holds and having prepared a data map, the organisation will have to undertake the formal process of confirming, documenting and filing the legal basis on which they collect personal data.

Select the two principles that apply

Correct

Hmmm. That's not right. If you get one more wrong, you’ll have to start again. If you need a recap, scroll to the top of the page to read again about different types of roles involved around GDPR.

ABC should only collect data it needs for a specific purpose.

Select the principle that applies

Correct

Hmmm. That's not right. If you get one more wrong, you’ll have to start again. If you need a recap, scroll to the top of the page to read again about different types of roles involved around GDPR.

ABC is required to ensure the process of capturing the data is robust and precludes a situation where data is corrupted or incorrectly recorded.

Select the two principles that apply

Correct

Hmmm. That's not right. If you get one more wrong, you’ll have to start again. If you need a recap, scroll to the top of the page to read again about different types of roles involved around GDPR.

ABC needs to specify the period of time that the organisation intends to hold specific elements of personal data, and the reasons behind those periods.

Select the principle that applies

Correct

Hmmm. That's not right. If you get one more wrong, you’ll have to start again. If you need a recap, scroll to the top of the page to read again about different types of roles involved around GDPR.

Well done!

Next Step