APC Mandatory - Data Management Flashcards
What is personal data
Uk GDPR Article 4
Personal data is any information relating to an identified or identifiable natural person (data subject), and an identifiable natural person is one who can be identified directly or indirectly
What is the freedom of information act
Gives individuals the right to access information held by public bodies
What are the exceptions to a FOI request
- Contrary to GDPR requirements
- It would prejudice a criminal matter
- CRCA overrides FOI request
What are the benefits to cloud based storage systems?
- Info backed up securely on encrypted servers
- Environmental friendly
- Could be cheaper than managing hard copy files
What is a non disclosure agreement?
Used to protect against disclosure or sharing of confidential data
Prior to sharing confidential info, the recipient will be requested to sign an NDA to ensure confidentiality
If 2 departments within ure firm were working for 2 rival companies how would u ensure data confidentiality
Per RICS Global COI 2018
1) Make client aware of risks involved with COI
2)Request written confirmation from both parties
3) Conflict management;
Ensure single communication lines to client, separate working locations for staff and NDA’s, also make sure data is secure
Key persons outlined in GDPR?
CONTROLLER
Determines process and means of processing of personal data (I.e employer processing employees data, employer considered controller)
PROCESSOR
Process data on behalf of controller (ie call centre on behalf of client).
DATA PROTECTION OFFICER
Under GDPR dpo is a required leadership role overseeing data protection
What are the 8 individual rights under GDPR
Article 5 Part II
Rights to
1) be informed
2) access information
3) rectify information
4) erasure
5) Restrict data processing
6) data portability
7) object
8) automated decision making and profiling
What things must companies put in place to ensure GDPR
Raise awareness
Review proceadures
Audits
CEW FS
How is data managed and protected within ure firm?
VOA policy CEW-FS
Clear desk policy
Encryption technology
Waste disposal for restrictive info/data
Fire wall protection
Security markings
What is GDPR?
Gives rights and protection to living data subjects over who holds their personal data and how that data is used
Name some exemptions to GDPR
Law enforcement
National Security
Domestic Purposes
What are the key principles of GDPR?
LDP ASIA
Lawful fair and transaction
Data minimisation
Purpose limitation
Accuracy
Storage limitations
Integrity and confidentiality
Accountability
Who is the responsible body for overseeing GDPR in the UK?
Information commissioner office
GDPR breach what happens?
Inform ICO within 72 hrs
Can be fined up to 20m euros or 4% of turnover whichever is greater
What is the purpose of CRCA 2005
Protect ratepayer confidentiality
What is Section 7 of the CRCA 2005
Sets out the VOA’s functions:
- Compilation and maintenance of rating lists and council tax lists
- The valuation of property
What is Section 10 of the CRCA 2005
Allows the VOA to provide a valuation of property:
- For any purpose relating to its function
- At the request of a public authority
RNP
How long can you store data for under the CRCA
No time limit but needs to be reasonable, necessary and propotinate
What act covers data in the UK
Data protection act 2018 and its amended version 2021 post brexit
What happens if you breach CRCA?
Sec 19
Maximum 2 Yr imprisonment or unlimited fine
Can you use someone else’s work
Under copyright designs and patents act 1988
Sec 50 allows for stat function
Sec 45 allows for judicial proceeding
If recive permission from copyright owner
In accordance with terms of publisher
Acknowledge source
What is the deadline once a FOI or SARS is requested?
Depends
GDPR - Should respond within 1 month (Article 12). This can be extended to 2 months where complex.
FOI - 20 working days
Which acts are relevant to data management
GDPR 2018
DPA 2018
CRCA 2005
EIR 2004 (covers foi relating to environmental matters)
Copyrights design and patents act 1988
FOI 2000
PRA 1958 (must manage data in accordance with FOI sec 46)
How does your employer store data?
CDB - local taxation and SDLT
EDRM- holds historic correspondence and plans
NBS holds taxation info for non standard properties
CWS holds CCA related information
Fines under GDPR
4% of global turnover
Or 20m euros
What is ISO 27001
First published in 2005 by International organisation for standardisation (ISO) recently revised in 2022.
Widely used global security framework focusing on data confidentiality,integrity and availability [CIA]. It involves audits followed by ongoing certification.
Helps organisations have a better approach to data security
What are the main differences between DPA and GDPR?
In summary, the GDPR serves as the foundational regulation for data protection in the EU, while the UK DPA 2018 adapts GDPR principles to the UK’s context, particularly after Brexit
(There is a new accountability requirement- you are required to show how you comply with the principles).
When did GDPR come into force
May 2018