🇬🇧 Chartered IT Professional (CITP) · subject

Chartered IT Professional (CITP) Law, Regulation and Governance Syllabus

Every chapter and topic of Law, Regulation and Governance examined in Chartered IT Professional (CITP) — 3 chapters, 9 topics and 20 sub-topics, plus 52 flashcards written against it.

3Chapters
9Topics
20Sub-topics
~10hEst. first pass
11%Of Chartered IT Professional (CITP)
52Flashcards

Law, Regulation and Governance syllabus — full chapter and topic list

Expand any chapter to see its topics and sub-topics. This is the whole examinable outline for Law, Regulation and Governance in Chartered IT Professional (CITP), not a summary of it.

  1. Data Protection and Privacy Law

    3 topics
    • UK GDPR and Data Protection Act 2018
      • Data protection principles
      • Lawful bases for processing
      • Data subject rights
    • Accountability and Compliance
      • Data protection impact assessments
      • Records of processing and breach reporting
      • Role of the ICO
    • Privacy by Design
      • Data minimisation and purpose limitation
      • International data transfers
  2. Computing and Intellectual Property Law

    3 topics
    • Computer Misuse and Cybercrime
      • Computer Misuse Act 1990
      • Unauthorised access and modification
    • Intellectual Property
      • Copyright, patents and trademarks
      • Software licensing and open source
    • Contract and Liability Law
      • Formation and terms of IT contracts
      • Consumer protection and online trading
  3. Corporate Governance and Compliance

    3 topics
    • IT Governance Frameworks
      • COBIT principles and components
      • Board accountability for technology
    • Regulatory and Sector Compliance
      • Sector regulation and standards
      • Audit and assurance
    • Accessibility and Equality Duties
      • Equality Act and accessibility regulations
      • WCAG and inclusive design obligations

Law, Regulation and Governance flashcards for Chartered IT Professional (CITP)

23 of 52 cards from the Law, Regulation and Governance deck — real questions with worked answers.

  1. What is the UK GDPR and how does it relate to EU GDPR?

    The UK GDPR is the UK's retained version of the EU General Data Protection Regulation, brought into UK law after Brexit via the European Union (Withdrawal) Act 2018. It mirrors the EU GDPR's principles but is supplemented and tailored by the Data Protection Act 2018, and is overseen by the UK Information Commissioner's Office (ICO).

  2. List the seven data protection principles under Article 5 of the UK GDPR.

    1) Lawfulness, fairness and transparency; 2) Purpose limitation; 3) Data minimisation; 4) Accuracy; 5) Storage limitation; 6) Integrity and confidentiality (security); 7) Accountability.

  3. Under UK GDPR, what is the definition of 'personal data'?

    Any information relating to an identified or identifiable natural person (the data subject). An identifiable person is one who can be identified directly or indirectly, e.g. by name, ID number, location data, online identifier, or factors specific to their physical, genetic, mental, economic, cultural or social identity.

  4. What are the six lawful bases for processing personal data under Article 6 of the UK GDPR?

    1) Consent; 2) Contract; 3) Legal obligation; 4) Vital interests; 5) Public task; 6) Legitimate interests.

  5. What categories count as 'special category data' under UK GDPR Article 9?

    Data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, plus genetic data, biometric data (for identification), data concerning health, and data concerning a person's sex life or sexual orientation.

  6. What is the standard time limit for responding to a Data Subject Access Request (DSAR) under UK GDPR?

    One calendar month from receipt of the request. It can be extended by up to a further two months for complex or numerous requests (giving a maximum of three months), and the response is normally provided free of charge.

  7. What are the maximum administrative fines under the UK GDPR?

    The higher tier is up to £17.5 million or 4% of total annual worldwide turnover, whichever is greater. The standard (lower) tier is up to £8.7 million or 2% of worldwide turnover, whichever is greater.

  8. Under UK GDPR, within what timeframe must a notifiable personal data breach be reported to the ICO?

    Without undue delay and, where feasible, no later than 72 hours after becoming aware of it. A breach need not be reported if it is unlikely to result in a risk to the rights and freedoms of individuals.

  9. When must affected individuals (data subjects) be notified of a personal data breach under UK GDPR?

    When the breach is likely to result in a high risk to the rights and freedoms of the individuals concerned. Notification must be made without undue delay.

  10. Name the individual rights granted to data subjects under the UK GDPR.

    Right to be informed; right of access; right to rectification; right to erasure ('right to be forgotten'); right to restrict processing; right to data portability; right to object; and rights related to automated decision-making and profiling.

  11. What is the distinction between a 'data controller' and a 'data processor'?

    A controller determines the purposes and means of processing personal data (the 'why' and 'how'). A processor acts on behalf of, and on the instructions of, the controller. Controllers carry primary accountability, though processors also have direct obligations under UK GDPR.

  12. What is the accountability principle under UK GDPR and how is it demonstrated?

    Accountability requires controllers to take responsibility for, and be able to demonstrate, compliance with the data protection principles. It is evidenced through documentation, policies, records of processing activities (RoPA), DPIAs, training, contracts, and appropriate technical and organisational measures.

  13. When is an organisation legally required to appoint a Data Protection Officer (DPO) under UK GDPR?

    When it is a public authority/body; when its core activities require regular and systematic monitoring of data subjects on a large scale; or when its core activities involve large-scale processing of special category data or criminal conviction data.

  14. What is a Record of Processing Activities (RoPA) and who must maintain one?

    A RoPA (Article 30) is documentation of an organisation's processing activities, including purposes, data categories, recipients, transfers, retention periods and security measures. Required for organisations with 250+ employees, and for smaller ones whose processing is not occasional, is high-risk, or involves special category/criminal data.

  15. What is a Data Protection Impact Assessment (DPIA) and when is it mandatory?

    A DPIA is a process to identify and minimise data protection risks of a project. It is mandatory where processing is likely to result in a high risk to individuals, e.g. systematic large-scale monitoring, large-scale special category processing, or large-scale automated decision-making with significant effects.

  16. What is the role of the Information Commissioner's Office (ICO)?

    The ICO is the UK's independent supervisory authority for data protection and information rights. It enforces the UK GDPR, DPA 2018, PECR and the Freedom of Information Act, issues guidance, investigates complaints, and can impose enforcement notices and fines.

  17. How does the Data Protection Act 2018 supplement the UK GDPR?

    The DPA 2018 fills in UK-specific details and derogations: it sets the age of consent for online services, defines exemptions, and provides separate regimes (Part 3 for law enforcement processing and Part 4 for intelligence services) not covered by UK GDPR.

  18. What is the principle of 'data minimisation'?

    Personal data collected must be adequate, relevant and limited to what is necessary in relation to the purposes for which it is processed. Organisations should not collect more data than they need.

  19. What is 'privacy by design and by default' under Article 25 of UK GDPR?

    Privacy by design requires data protection measures to be integrated into processing activities and systems from the outset. Privacy by default requires that, by default, only personal data necessary for each specific purpose is processed (minimal data, limited access, limited retention).

  20. Name the foundational privacy-by-design principles articulated by Ann Cavoukian.

    1) Proactive not reactive (preventative); 2) Privacy as the default setting; 3) Privacy embedded into design; 4) Full functionality (positive-sum, not zero-sum); 5) End-to-end security (full lifecycle protection); 6) Visibility and transparency; 7) Respect for user privacy (user-centric).

  21. What are pseudonymisation and anonymisation, and how do they differ under data protection law?

    Pseudonymisation replaces identifying fields with artificial identifiers so data can no longer be attributed to a subject without additional information held separately — it remains personal data. Anonymisation irreversibly prevents identification, so the data falls outside UK GDPR scope.

  22. What three offences does the Computer Misuse Act 1990 create?

    Section 1: unauthorised access to computer material; Section 2: unauthorised access with intent to commit or facilitate further offences; Section 3: unauthorised acts with intent to impair, or with recklessness as to impairing, the operation of a computer (e.g. malware, DoS).

  23. What additional offence was added to the Computer Misuse Act by the Police and Justice Act 2006?

    Section 3A: making, supplying or obtaining articles (e.g. hacking tools or malware) for use in committing computer misuse offences under sections 1 or 3.

See more Law, Regulation and Governance flashcards →

Planning Law, Regulation and Governance for Chartered IT Professional (CITP)

Law, Regulation and Governance is about 11% of the Chartered IT Professional (CITP) syllabus by topic count — 9 of 83 topics, spread over 3 chapters. At roughly 45 minutes per topic plus 12 minutes per sub-topic, a first pass runs to about 10 hours.

The heaviest chapters are Data Protection and Privacy Law (3 topics), Computing and Intellectual Property Law (3 topics), Corporate Governance and Compliance (3 topics) . Front-load those while your energy is high; the short chapters are better revision filler later.

Work top-down: read the chapter, then tick topics off individually rather than marking the whole chapter done. Sub-topics are where silent gaps hide.

Law, Regulation and Governance (Chartered IT Professional (CITP)) FAQ

What is in the Chartered IT Professional (CITP) Law, Regulation and Governance syllabus?

Law, Regulation and Governance is split into 3 chapters — Data Protection and Privacy Law, Computing and Intellectual Property Law and Corporate Governance and Compliance, containing 9 topics and 20 sub-topics in total.

How is Law, Regulation and Governance structured in the Chartered IT Professional (CITP) syllabus?

3 chapters. Law, Regulation and Governance accounts for about 11% of the topics in the whole Chartered IT Professional (CITP) syllabus (9 of 83).

How long should I spend on Law, Regulation and Governance for Chartered IT Professional (CITP)?

Budget around 10 hours for a first pass through Law, Regulation and Governance — about 45 minutes per topic plus 12 minutes per sub-topic across its 9 topics. Add revision cycles on top.

Are there flashcards for Chartered IT Professional (CITP) Law, Regulation and Governance?

Yes — a 52-card Law, Regulation and Governance deck. Sample cards are printed on this page, and the full deck is free in the Examius app with spaced repetition scheduling.