What rights do customers have under UK GDPR in relation to their data?

Prepare for the London Institute of Banking and Finance Exam with interactive quizzes, flashcards, and detailed explanations. Excel in your exams!

Multiple Choice

What rights do customers have under UK GDPR in relation to their data?

Explanation:
Under UK GDPR, customers have a set of rights that give them real control over their personal data. These rights include access to the data held about them, correction of any inaccuracies, erasure where appropriate, restriction of processing in certain situations, the ability to receive their data in a portable format so it can be moved to another organisation, and the right to object to processing (for example, to direct marketing or to processing based on legitimate interests). These rights are exercised by making requests to the data controller, who must respond within a month (with possible extensions in complex cases) and provide the data in a readable form for portability. The other options don’t fit because they describe actions not granted as personal data rights under GDPR. An annual audit of employees isn’t a data subject right; organisations conduct internal or statutory audits rather than individual rights. A firm’s data retention policy isn’t something individuals set as a right. And requesting free credit reports from all banks isn’t a GDPR right as stated; you can access your own information held by banks or credit reference agencies under applicable rules, but there isn’t a blanket right to obtain free reports from every bank automatically.

Under UK GDPR, customers have a set of rights that give them real control over their personal data. These rights include access to the data held about them, correction of any inaccuracies, erasure where appropriate, restriction of processing in certain situations, the ability to receive their data in a portable format so it can be moved to another organisation, and the right to object to processing (for example, to direct marketing or to processing based on legitimate interests). These rights are exercised by making requests to the data controller, who must respond within a month (with possible extensions in complex cases) and provide the data in a readable form for portability.

The other options don’t fit because they describe actions not granted as personal data rights under GDPR. An annual audit of employees isn’t a data subject right; organisations conduct internal or statutory audits rather than individual rights. A firm’s data retention policy isn’t something individuals set as a right. And requesting free credit reports from all banks isn’t a GDPR right as stated; you can access your own information held by banks or credit reference agencies under applicable rules, but there isn’t a blanket right to obtain free reports from every bank automatically.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy