Download presentation
Presentation is loading. Please wait.
1
Security of, privacy of and access to personal/confidential information/data
2
Anonymised information
Information about individuals without mentioning the person by name is called anonymised information. Where anonymised information would be sufficient for a particular purpose, organisations should always omit personal details wherever possible.
3
Aggregated information
Aggregated information is where personal details of individuals are combined to provide information without naming those individuals. This could be in the form of medical information regarding a list of patients who are suffering from a certain illness.
4
Duty of confidence As was mentioned above, organisations should include a duty of confidence clause in employment contracts. Individuals who feel that their confidential data has been made public (i.e. their confidentiality has been breached) should complain to the organisation.
5
Duty of fidelity An employee must be loyal
to their employer for so long as they work for them. That means that they must not tell any rival companies about their work. This does not mean that the information is confidential. Once an employee leaves a company they are free to use the skills and knowledge with their new employer.
6
Why was suspected child offender allowed to work in a school, which lead to him murdering these two girls?
7
Because he was only ‘suspected’ and never found guilty.
The police wouldn’t realise this data to the school, due to data protection
8
What is the Data protection legislation?
Data protection acts exist in most countries. These set down rules for keeping data private as well as confidential. Most countries have similar sets of data protection rules.
9
What are the eight principles of the DPA?
Personal data shall be processed fairly and lawfully. Personal data shall be obtained only for a lawful purpose), and shall not be used for anything other than that purpos(es)
10
Personal data shall be adequate, relevant and not excessive in relation to the purpose (or purposes) for which they are processed.
11
Personal data shall be accurate and, where
necessary, kept up to date. Personal data processed for any purpose shall not be kept for longer than is necessary for that purpose.
12
Personal data shall be processed in accordance with the rights of data subjects.
Appropriate measures shall be taken against unauthorised or unlawful processing data. Including loss / leaks.
13
Personal data shall not be transferred to a country outside the European Economic Area unless that country guarantees the same level of data protection.
14
Phishing My username My password
15
Pharming Instead of an email being sent with a fake link.
Imagine you goto HSBC.ae and the site has been ‘hacked’. It looks correct But you login and it doesn’t work. Pharming is when the site or DNS is hacked, this is down to banks to check this
16
Spyware Software that is accidently downloaded.
Allows ‘creator of the software’ to be able to spy on you. Most anti-virus will detect spyware as well.
Similar presentations
© 2024 SlidePlayer.com. Inc.
All rights reserved.