Free ETCP Security in Cloud Environments Questions and Answers — Questions and Answers
Question 1: Which of the following should you NOT do with data whilst at work?
- Access ‘personal data’ that you do not need for your work
- Use someone’s ‘personal data’ to complete your work without asking permission from the individual
- Keep ‘sensitive data’ after being given permission by the individual concerned
- Record ‘personal data’ for your own use outside of work
- A and D (Correct answer)
Correct answer: A and D
Data protection regulations strictly govern how personal and sensitive data can be handled. Accessing 'personal data' not needed for work (A) is a breach of the 'need-to-know' principle, and recording 'personal data' for personal use outside of work (D) is a severe misuse and violation of privacy and data security policies. Both actions are explicitly prohibited to prevent unauthorized access, disclosure, and potential misuse of information.
Question 2: Which of the following does not constitute ‘sensitive data’? Data consisting of information about....
- ...an individual's religious beliefs
- ...an individual's home address (Correct answer)
- ...an individual's political opinions
- ...an individual's criminal convictions
Correct answer: ...an individual's home address
Under data protection laws like GDPR, 'sensitive data' refers to specific categories requiring extra protection, such as information about an individual's religious beliefs, political opinions, or criminal convictions. An individual's home address, while considered 'personal data' because it can identify a person, does not fall into these special categories of 'sensitive data'. Sensitive data typically carries a higher risk of discrimination or harm if misused.
Question 3: Who is the First Info Data Protection Officer?
- Cassie Dunton
- Becky Simpson
- Debbie Smith (Correct answer)
- Rebecca Jenkins
Correct answer: Debbie Smith
This question asks for a specific factual recall related to the Ericsson Technical Certification Program (ETCP) and its internal data protection roles. Debbie Smith is the designated First Info Data Protection Officer for Ericsson. This information would be learned through company-specific training or documentation provided as part of the ETCP.
Question 4: What is 'personal data' considered to be under the DPA?
- Height, weight and appearance
- Racial or ethnic origin, religious beliefs and political opinion
- Physical or mental health and criminal offences
- Name, address contact details and date of birth (Correct answer)
Correct answer: Name, address contact details and date of birth
Under the Data Protection Act (DPA) and similar regulations like GDPR, 'personal data' is defined as any information relating to an identified or identifiable natural person. This includes common identifiers such as a person's name, home address, contact details (like phone number or email), and date of birth, as these pieces of information can directly or indirectly identify an individual. Other options list categories that are either too general or fall under 'sensitive data'.
Question 5: What are we not allowed to do with 'sensitive data'?
- Collect it without permission
- Store it without permission
- Disclose it without appropriate checks
- All of the above (Correct answer)
Correct answer: All of the above
'Sensitive data' is subject to the highest level of protection under data privacy regulations. Organizations are strictly prohibited from collecting, storing, or disclosing sensitive data without explicit and informed consent from the individual, or a clear legal basis. Failing to obtain permission for collection or storage, or disclosing it without appropriate checks, constitutes a serious breach of data protection principles and can lead to significant penalties.
Question 6: What do we charge a customer that wants us to send them any data that we hold about them?
- £5
- £5 per item of data
- £10 (Correct answer)
- £20
Correct answer: £10
This question refers to the fee charged for a Subject Access Request (SAR) under specific data protection legislation, likely the Data Protection Act 1998 (DPA 1998) in the UK before GDPR. Under the DPA 1998, organizations were permitted to charge a statutory fee, typically £10, for processing a SAR. While GDPR generally removed this fee, the context suggests this specific fee was applicable.
Question 7: What form must you send the customer if they want any data that we hold about them?
- A 'Subject Access Request' form (Correct answer)
- A 'Change Request' form
- A 'Data Capture' form
- A 'Declaration of Non-Receipt' form
Correct answer: A 'Subject Access Request' form
When an individual wants to obtain a copy of the personal data an organization holds about them, they make a 'Subject Access Request' (SAR). This is a fundamental right under data protection laws like the Data Protection Act and GDPR. Organizations typically have a formal process, often involving a specific form, to handle these requests to ensure proper identification of the requester and efficient processing of the data.
Which of the following should you NOT do with data whilst at work?