Data Management Flashcards

1
Q

What is GDPR

A

GDPR is short for the EU General Data Protection Regulation which is legislation designed to harmonise data protection regulations across the EU and give individuals greater control over the privacy and use of their data.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is the Data Protection Act 2018

A

Data Protection Act 2018 is the UK’s implementation of the EUs GDPR. Since the UK left the EU in Jan 2021, now have UK GDPR which mirrors the EU version.

Covers all aspects of general data and aspects of personal data (reflects modern data usage)
It controls how your personal information is used by organizations, businesses and the government.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Name previous act on Data Protection

A

Data Protection Act 1998

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is personal data

A

includes name, address, date of birth, CVs, appraisals, emails, texts

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Name the main changes for data protection

A
  1. Fines - now max fine is higher of 20mn euros or 4% turnover
  2. Accountability - businesses have to clearly demonstrate compliance
  3. Breach Notification - breaches reported within 72 hours
  4. Right to be forgotten - gives individuals greater controls over the use and management of their data - deleting records rather than archiving
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Who controls data protection in Uk

A

Information Commissioners Office (ICO)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is the role of a data controller

A

Data controller decides on the purpose for which data is being collected, held or processed primary responsibility for managing and protecting the data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is the role of a data protection officier

A

Data Protection Officer - primary contact, mandatory for large organisations - overseeing a company’s data protection strategy and its implementation to comply with GDPR requirements

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Name the 6 core principles for data protection

A
  1. Data must be processed in a lawful and transparent manner
  2. Legitimate purpose - personal data must be obtained for specified, explicit and legitimate purposes only
  3. Data should be relevant and limited to what is necessary
  4. Accurate and upto date
  5. Limited storage
  6. Secure
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Describe examples of a data breach

A

Loss of file, memory stick, laptop, phone, hacking, stolen/misused password

Must report breach within 72 hours

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Name 8 rights under GDPR

A
  1. Right to be informed
  2. Right of access
  3. Right to rectification
  4. Right to erasure
  5. Right to restrict processing
  6. Right to data portability
  7. Right to object
  8. Rights to automated decision making and profiling.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

How is CJ compliant with GDPR

A
  • Lock computers when not at desk
  • All paper documentation is filed in locked cabinets
  • When onsite, prevent taking personal information on paperwork
  • Prevent sharing passwords
  • Don’t have paper files unless really necessary
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

How does CJ ensure confidentiality

A

– good security of electronic data (firewalls, encryption and passwords), Non Disclosure Agreements

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is a non disclosure agreement

A

Non disclosure Agreements are a legal contract. It sets out how you share information or ideas in confidence. They commonly last 3-5 years and ensures information is kept confidential.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is the main purpose of teh Data Protection Act 2018

A

to set the guidelines for companies for the collection, processing, storage and protection of personal data and to give individuals the rights to access, and correct their personal data and prevent it from being used for marketing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Name RICS new guidance on data

A

New RICS Guidance – Data Handling and Prevention of Cyber Crime (currently in consultation)

17
Q

What is the freedom of information act 2000

A
  • Gives individuals the rights to access information held by public bodies.
  • Public bodies (government / Local authorities) are required to issue information held on individuals within 20 days of request.