Data management Flashcards

1
Q

What legislation covers data protection?

A

General Data Protection Regulation (GDPR)

In the UK, the Data Protection Act 2018 (DPA) covers processing that does not fall within EU law, for example relating to immigration and national security.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is the Data Protection Act?

A

Controls how your personal information is used by organisations, businesses or the government

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

When did GDPR come into affect?

A

25 May 2018

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Have you completed any training on GRPR?

A

Yes. We have to undertake mandatory GDPR training every two years.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What data does your company have?

A
  • Details of current, past and prospective employees, clients, suppliers and others that we communicate with.
  • Tenants
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is personal data?

A

Personal data means any information relating to an identified or identifiable natural person (‘data subject’);

An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person; (Source: Article 4 GDPR)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Who ensures compliance?

A

Nominated Data Protection Officer (DPO)

The DPO is supported by a core team who provide assistance with a number of different areas relating to the protection of information and who can help with queries.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Who does Freedom of Information Act Apply to?

A

Public right of access to information held by public authorities.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Does GDPR apply post Brexit?

A

Yes, many aspects of GDPR will be converted into UK Law on 1st Jan 2021 under the titles UK GDPR. in turn companies will still need to comply? Double check this.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What are the maximum fines (UK GDPR), how are the fines calculated?

A

£17.5 million

or 4% of the total annual worldwide turnover in the preceding financial year, whichever is higher.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What 10 tips to ensure compliance with GDPR?

A
  1. Prepare diligently to ensure compliance
  2. Assess any privacy risks inherent in business processes/activities
  3. Involve IT support to make appropriate changes
  4. Provide staff training and support on data security
  5. Appoint a Data Protection Officer if required by GDPR
  6. Ensure you have adequate systems to deal with a breach and subsequent notification to the ICO (within 72 hours)
  7. Do your systems comply with all GDPR principles, including the right to be forgotten
  8. Update your internet security, e.g. virus protection, including on desktops, laptops and mobile phones
  9. Ensure any data already held is up to date and compliant with GDPR
  10. Can you release personal data promptly if a subject access request is made?
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Who oversee information rights in the UK?

A

ICO - Information Commissioners Office

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

How do you ensure data you hold on clients is kept secure and confidential?

A
  • I use secure documents that are stored on password protected machines and servers.
  • I also only keep the information I need and use it for the purpose it has been collected without passing it on unless I have approval prior.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What are the 7 GDPR principles? -

(LFT-A-DM-SL-PL-A-S)

A
  1. Lawfulness, fairness and transparency – leave the individual fully informed
  2. Accuracy – where necessary kept up to date, erase inaccurate personal data without dela
  3. Data minimisation – collect the minimum data you need
  4. Storage limitation – Retain the data for a necessary limited period and then eras
  5. Purpose limitation – must inform your clients about the purpose of the data collection
  6. Accountability – Record and prove compliance
  7. Security - Integrity and confidentiality – Keep it secure, locked filing cabinet or fire wall
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

How have you changed the way you managed data during COVID-19 and home working?

A
  • No paperwork/documents
  • Only use work equipment
  • Regular password changes
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

How do DPA and GDPR differ?

A

Accountability to ensure that data is kept in accordance with the principles of GDPR

Tougher penalties for non-compliance
Wider definition of personal data

Non-EU organisations holding EU-related personal data will need to comply

Parental consent required for holding personal data of <16s

Active consent must be required to hold data, i.e. silence does not equal consent

Data breaches must be notified to ICO within 72 hours of awareness, unless exceptional circumstances apply

Risk-based reviews (Privacy Impact Assessments) must be undertaken for high risk activities

Right to be forgotten introduced

Requirements for electronic data portability if a data request is submitted

Compliance/privacy by design must be included within systems and processes, including staff training and contractual clauses

Additional liabilities placed on both data controllers and processors

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

How do you ensure the data that you hold on your clients is kept secure and confidential?

A
  • Limit access to sensitive data use smart passwords to resident details.
  • Internal ICT perform regular updates for firewalls and antivirus protection.
  • Internal servers permission for access to only those who need the information. Permission removed when you no longer need access to the information.
18
Q

Why do you keep company data for 12 years?

A
  • It is a requirement of our PII insurance that all contracts under deed are kept for a minimum of 12 years and under hand for 6 years.
  • I am aware of the limitation act to claims which can be brought about up to 15 years after the act of negligence.
19
Q

What is project extranet?

A

A computer network that allows controlled access from the outside for specific project purposes. Essentially is a system that allows individuals outside the company to view project files on a secure platform. (Revit)

20
Q

What is BIM?

A

Building Information Modelling. Software creating 3D models that allow industry professionals to better plan, design, construct and mange buildings/infrastructure.

21
Q

What are the disadvantages of BIM?

A

Very expensive and not all construction professionals use it and therefore less experts.

22
Q

What should you do if there is a data breach?

A

Inform the Information Commissioner’s Office not later than 72 hours after becoming aware of it.

23
Q

What are ISO Standards?

A

International Organisation for Standardisation

  • An international standard setting body of representatives from varying national standards
24
Q

What is the limitations act?

A

The Limitation Act 1980

  • Act of the Parliament of the United Kingdom applicable only to England and Wales.
  • It is a statute of limitations which provides timescales within which action may be taken for breaches of the law.
25
Q

Can you give me some example of the data you manage ?

A
  • Client details
  • Project details
  • Contractor details
  • Project finances
26
Q

What are the GDPR rights? (IARERPO)

A
  • The right to be informed
  • The right of access
  • The right to rectification
  • The right to erasure
  • The right to restrict processing
  • The right to data portability
  • The right to object
  • Rights in relation to automated decision making and profiling
27
Q

Can you expand on what BCIS is?

A

The Building Cost Information Service

  • Provides cost and price data for the UK construction industry. It is a part of the Royal Institution of Chartered Surveyors.
28
Q

What are the benefits of using external data sources such as BCIS etc?

A
  • Industry wide data
  • Standardisation
  • Data management
29
Q

Why is it important that we safeguard information?

A

As personal data can be used in various ways

30
Q

What kind of information is ‘sensitive’ information?

A

Health records, financial information, address, educational records etc

31
Q

Why do the General Data Protection Regulations 2018 exist?

A

To control how your personal information is used by organisations, businesses or the government

32
Q

How do you ensure the data that you hold on your clients is kept secure and confidential?

A
  • We use an only system to carry out checks
  • Operate a clear desk policy
  • Shredding of details etc
  • Two factor authentication of IT systems
33
Q

How long do you keep client’s data and how do you ensure it is deleted when necessary?

A

Dependent on the type of data and the contract:

  • Under hand - 6 years
  • Under deed - 12 years
  • Limitations act – 15 years
34
Q

What types of breaches are there under GDPR?

(DDA)

A
  • Disclosure
  • Destruction
  • Alteration
35
Q

What is copyright?

A
  • Copyright is an intellectual property right assigned automatically to the creator.
  • It prevents unauthorised copying and publishing of an original work.
  • Copyright applies to research data and plays a role when creating, sharing and reusing data.
36
Q

What is a controller?

A

‘controller’ means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.

37
Q

What is processor?

A

‘processor’ means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.

38
Q

What is the role of a controller?

A

Controllers make decisions about processing activities. They exercise overall control of the personal data being processed and are ultimately in charge of and responsible for the processing

39
Q

What is the role of a processor?

A

Processors act on behalf of the relevant controller and under their authority. In doing so, they serve the controller’s interests rather than their own.

40
Q

What do you in the event of a data breach; what control measures are in place?

A

You must report a notifiable breach to the ICO without undue delay, but not later than 72 hours after becoming aware of it. If you take longer than this, you must give reasons for the delay.

Antivirus Protection
Email system is traffic monitored filtering spam/fraudulent emails
Data Protection Team - we must report to our Information, Governance & Feedback Information Team immediately (within 72 hours).
Also report to the IT Service Desk immediately.
Fill out Personal Data Breach Template

If I am in doubt, I would go to the Information Commissioners Office website for further information.

41
Q

What is data protection impact assessment?

A

Data Protection Impact Assessment (DPIA) is a process to help you identify and minimise the data protection risks of a project.

42
Q

What do you do contractually with regards to data?

A

Clause is altered within the contract (1 of 2) depending on whether data collection will form part of the project in any way.