Data Management Flashcards

1
Q

What is GDPR?

A

General Data Protection Regulations (2016) effective May 2018

It aims to create a singe data protection regime for the EU.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

How is data protection legislated in the UK?

A

UK GDPR 2020

Data Protection Act 2018 implemented GDPR (2016)

Replaced DPA Act 1998

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are the principles under the Data Protection Act 2018?

A
  1. Used lawfully, fairly and transparently
  2. Collected for specified and legitimate purposes
  3. Accurate
  4. Retained for no longer than is necessary
  5. Processed securely including the protection against unlawful use, loss or destruction.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are the 8 individual rights under GDPR?

A
  1. Informed
  2. Access
  3. Rectification
  4. Erasure
  5. Restrict Processing
  6. Data Portability (their own use)
  7. Object
  8. Automated Decision Making and Profiling (Insurance companies)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Who are the key persons outlined within GDPR?

A

Controller - Determine the purposes and means of the processing of personal data. (Employer)

Processor - Processes personal data on behalf of the controller. (Call centre)

Data Protection Officer - Oversees the data protection approach, strategy and its implementation. Leadership role required by GDPR (2016).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What are some changes brought about by GDPR?

A

Data Controller responsible for GDPR

Individuals can request what personal data is held and request it is deleted

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Who is GDPR policed by?

A

Information Commissioners Office (ISO)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What do you know about forthcoming data legislation?

A

On 8 March 2023, the Government published the Data Protection and Digital Information Bill (2nd).

The New Bill looks to reform the current UK data protection framework comprising of UK GDPR, the DPA 2018 and the Privacy and Electronic Communications Regulations 2003.

Intended to make data protection legislation simpler for businesses to understand and implement.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is the Freedom of Information Act 2000?

A

Primary piece of UK legislation controlling the access to official information

Allows an individual to request access to information held by a public body.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What are the timescales for requesting information under the Freedom of Information Act 2000?

A

20 working days in the requested format
A fee may be charged

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is personal data?

A

Under GDPR, Personal data is any information which is related to an identified or identifiable natural person.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is a non-disclosure agreement?

A

NDAs are used to protect against the disclosure or sharing of any confidential data.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is a subject access request?

A

SAR - demand that the individual be given all information that a company holds on them.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is copyright?

A

A set of exclusive rights granted to the author or creator of any original work, including the right to copy which can be licensed, assigned or transferred.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is meant by confidentiality?

A

Where information is provided, but is subject to confidence and not shared without permission.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is Meta Data?

A

Meta Data is information about a specific piece of data.

When sharing a document, the Meta Data could include information about the author, file size, date the document was created etc.

Meta Data should be afforded the same level of care as other confidential information.

17
Q

What are the benefits of cloud based storage systems?

A
  • Information is backed up on securely encrypted services.
  • Accessibility can be managed via online settings.
  • Often cheaper than physically storing files.
  • ## Multiple users can access the same document.
18
Q

What different sources of information do you use in your day to day work?

A
  • RICS publications
  • Comparable search engines
  • Background enquiry search engines
  • BCIS
19
Q

How do you manage these sourced of information to ensure compliance with the legislation?

A
  • Electronic information is kept securely on encrypted servers.
  • Locking my computer, regularly updating passwords and undertaking cyber security training.
20
Q

How does your firm ensure compliance with Data Protection Act 2018?

A
  • Only retain data needed for day to day operations
  • If data is retained, the person should be kept informed and advised on why they have it.
  • Hold data securely
  • Keep information up to date and delete information no longer needed.
21
Q

What data is held in your office?

A

Employee data - personal information

Client Data - contact details, leases, plans and deeds.

Company Data - Accounts, ToE and instructions.

22
Q

What do you need to do if you have a data breach?

A

Must report to ICO within 72 hours where there is a loss of personal data and risk of harm to individuals.

23
Q

What are the fines for non-compliance with GDPR?

A

Maximum fine of £17.5 million or 4% of annual turnover for infringements.

UK ICO - alternative actions
1. Issue warnings
2. Imposing a temporary or permanent ban on data processing
3. Ordering the rectification, restriction or erasure of data.
4. Suspending data transfers to third countries.

24
Q

Describe a time you have used property records to communicate complex, reasoned advice?

A

Post Office Truro
- Photographic evidence - size of property/visibility
- Evidence schedules - comparable rents at AVD
- Analyse - RVs and tone
- Location Map - pitch

25
Q

What is some best practice to employ in managing data?

A
  • Cross reference with hard copy/verification
  • IT System maintenance - back up
  • Audit trail