Data Management Flashcards
Principles of GDPR and DPA (6 Principles)
Information used lawfully, fairly and transparently.
Collected for specified, explicit and legitimate purpose.
Adequate, relevant and limited to necessity.
Accurate (kept up to date)
Kept no longer than necessary
Kept safe
Individual Rights of GDPR and DPA (8 key points)
To be informed
To access
To rectification
To erasure
To restrict processing
To data portability
To object
To automated decision making & profiling
GDPR and DPA Penalties
Fines (4% of annual global turnover or 20 million euros)
What is ISO 9001:2015
Sets requirements on how firms should control data and documents relevant to the service they provide.
Sets requirements for a company’s Quality Management System (QMS), which is about the management of the entire enterprise and its operational processes.
What security measure do you have for storing electronic data?
Only available from internal intra net which is password protected.
What sources of data are available in your field of expertise?
- Comparable sales data from MoveMachine, Rightmove Plus, Propvals etc.
- SEPA flood maps.
- Coal Mining maps from Coal Authority.
- Radon maps
- OS Maps
What is the most appropriate way to store client information in house?
- Password protected with encryption behind firewalls, if digitally stored
- Lock and key in house or a secure storage facility offsite.
What is GDPR?
It replaced the Data Protection Act 1998 and is a regulation in EU law. It gives citizens more control over their personal data and how it is used as well as improving security of stored data so that it is not freely shared with third parties without informed consent
When did GDPR come in to effect?
25th May 2018
What type of data cannot be stored or kept and should be shredded or professionally disposed of and why?
Personal data should be only stored for as necessary to process. Organisations must ensure data is deleted when no longer required to ensure it will not be inaccurate or out of date.
How do the recent changes in GDPR affect your day to day activities?
Our department has been relatively unaffected as our processes were appropriate under GDPR. However, I am aware that we have had to re-issue consent forms to ensure we are compliant when sending out mail shots to clients.
Are you required to keep certain documents for any length of time?
Yes files should be retained for a minimum of 6 years.