Data Management Flashcards

1
Q

What does GDPR stand for ?

A

General Data Protection Regulation (how we collect and process personal data)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

When did GDPR come into affect ?

A

25 May 2018 (UK).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are the maximum fines (UK GDPR) , how are the fines calculated?

A

• £17.5 million or 4% of the total annual worldwide turnover in the preceding financial year, whichever is higher

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Have you completed any training on GDPR ? what did you learn ?

A

Yes, please see CPD.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What legislation covers data protection in the UK ?

A

Data Protection Act 2018 and UK GDPR

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Who does Freedom of Information Act Apply to?

A

Public right of access to information held by public authorities.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Does GDPR apply post Brexit ?

A

Converted into UK Law on 1st Jan 2021 under the title UK GDPR.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What will the changes include (GDPR post Brexit)?

A

UK government will control the UK GDPR as opposed to the European union.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Who oversee information rights in the UK ?

A

ICO - Information Commissioners Office

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What happens if you are sharing or processing data from the EU ?

A

Adhere to :
• UK GDPR
• EU GDPR
• Data Protection Act 2018

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Who enforces the data protection ?

A

Information commissioners office - ICO

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

How do you ensure data you hold on clients is kept secure and confidential ?

A

1) Smart passwords/Firewalls/Anti-virus software.
2) Limit access to sensitive data.
3) Update security

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What are the 7 GDPR principles? - LADSPAS

A
  • Lawfulness, fairness and transparency – leave the individual fully informed
  • Accuracy – where necessary kept up to date, erase inaccurate personal data without delay
  • Data minimisation – collect the minimum data you need
  • Storage limitation – Retain the data for a necessary limited period and then eras
  • Purpose limitation – must inform your clients about the purpose of the data collection
  • Accountability – Record and prove compliance
  • Security - Integrity and confidentiality – Keep it secure, locked filing cabinet or fire wall
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

How have you changed the way you managed data during COVID 19 and home working ?

A

1) Only use work equipment
2) The storage of files/documents to be locked away,
3) Regular update on password protected equipment etc.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Why do you keep company data for 12 years?

A

PII insurance requirement (contracts under deed are kept for a minimum of 12 years and under hand for 6 years).

I am aware of the limitation act to claims which can be brought about up to 15 years after the act of negligence.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is project extranet?

A

Network that allows controlled access from the outside for specific project purposes.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

What is BIM?

A

Building Information Modelling. Software creating 3D models that allow industry professionals to better plan, design, construct and mange buildings/infrastructure.

18
Q

What are the disadvantages of BIM?

A

Very expensive

Lack of use = less experts

19
Q

How does BIM effect your role as a CA?

A

I’ve not used it but I would imagine that it simplifies the process by theoretically reducing the amount of variations required.

20
Q

What should you do if there is a data breach ?

A

Inform the Information Commissioner’s Office… no later than 72 hours after becoming aware of it.

21
Q

What are ISO Standards ?

A

International Organisation for Standardisation.
An international standard setting body of representatives from varying national standards.
• ISO 9000 – Quality Management Systems
• ISO 8000 – Data Quality

22
Q

What is the limitations act ?

A

The Limitation Act 1980 is an Act of the Parliament applicable only to England and Wales. It is a statute of limitations which provides timescales within which action may be taken for breaches of the law.

23
Q

What year was the Limitation Act published?

A

1980

24
Q

Can you give me some example of the data you manage ?

A
  • Client details
  • Contact details
  • Project details
  • Complaints
25
Q

What is personal data ?

A

Personal data only includes information relating to natural persons who:
• can be identified or who are identifiable, directly from the information in question; or
• who can be indirectly identified from that information in combination with other information.

26
Q

What are a persons right under the Data Protection GDPR rights ?

A
  • The right to be informed
  • The right of access
  • The right to rectification
  • The right to erasure
  • The right to restrict processing
  • The right to data portability
  • The right to object
  • Rights in relation to automated decision making and profiling
27
Q

What is the process if there is a data breach ?

A

Duty on all organisation’s to report certain personal data breaches to the relevant supervisory authority (72 hours).
• If high risk of adversely affecting individuals’ rights and freedoms, you must also inform those individuals without undue delay.
• Robust breach detection, investigation and internal reporting procedures in place.
• Keep a record of any personal data breaches (regardless of notification).

28
Q

Can you expand on what BCIS is ?

A

The Building Cost Information Service: •cost and price data for the UK construction industry.

29
Q

What are the principles of the Data Protection Act 2018 ?

A
LADSPAI
• Lawfulness, fairness, and transparency. 
• Accuracy.
• Data minimization.
• Storage limitation.
• Purpose limitation.
• Accountability.
• Integrity and confidentiality.
30
Q

What is the Data Protection Act 2018 ?

A

Controls how your personal information is used (organisations, businesses or the government).

31
Q

What are the principles of the data protection act ? PCRCDM

A
  • Proportionality
  • Commitment (Top Level)
  • Risk assessment
  • Communication
  • Due Diligence
  • Monitor and Review
32
Q

Why is it important that we safeguard information?

A

Can be used maliciously.

33
Q

What kind of information is ‘sensitive’ information?

A

Health records,
Financial information
Address

34
Q

What are the benefits of using external data sources such as BCIS etc?

A
  • Industry wide data
  • Standardisation
  • Data management
35
Q

What does your company do to ensure a clients information is kept secure and confidential ?

A
  • Operate a clear desk policy
  • Shredding of details etc
  • Two factor authentication of IT systems
36
Q

How long do you keep client’s data and how do you ensure it is deleted when necessary?

A

Dependent on the type of data and the contract
• Under hand - 6 years
• Under deed - 12 years
• Limitations act – 15 years

37
Q

What types of breaches are there under GDPR ? DDA

A
  • Disclosure
  • Destruction
  • Alteration
38
Q

What is personal information ?

A
  • Address
  • DOB
  • Bank details
39
Q

What is sensitive information/data ?

A
  • Medical records

* Sexual orientation

40
Q

Why does using standard templates such as CAD and Reports assist your company?

A

Flexibility,
Easy to update (centrally),
Provide consistency = professional
Easily tracked and updated.

41
Q

Who are the key persons outlined within GDPR?

A

1) CONTROLLER (determines purpose and means of processing personal data- EMPLOYER)
2) PROCESSOR- (Processes data on behalf of the controller- call centre)
3) Data Protection Officer (DPO)- Leadership role-overseeing data protection approach, strategy, implementation.