Data Management Flashcards

1
Q

What does the Data Protection act (2018) cover?

A

The Data Protection Act 2018 is the UK implementation of the GDPR.
Controls how personal information can be used and your rights to ask for information about yourself
Sets out the need to use information;
- Fairly
- Lawfully
- Transparently

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

How do you comply with GDPR and the Data Protection Act 2018 in your role/ when using Landstack, Costar etc?

A
  • Ensure access to data is only granted to people who require it
  • I ensure that all files and folders are labelled correctly.
  • Data is only stored for as long as necessary – either for the length of time needed for a project or to comply with statutory regulations e.g money laundering
  • Secure confidential and sensitive information with password encryption
  • Only share data using secure systems
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

How do you validate information?

A

Source – is the source credible and reliable
Time – how recent is the information gathered is it as up to date as possible
Relevance – is the information gather directly related to your need or purpose
Sense check – try to verify the information by cross referencing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are the penalties for breach of GDPR?

A

Fined up to 4% of annual global turnover or 17.5million euros

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are the ways you can manage data?

A

Excel/outlook

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

How long should files be kept for?

A

No longer than required.
6 years from end of relationship with client.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is the freedom of information act?

A
  • Gives individuals right of access to info held by public bodies
  • Public body must tell any individual requesting sight of info whether it hold it.
  • Public body must reply within 20 working days
  • It can charge for the provision of the info
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

How can the security of the electronic data be improved?

A

Firewalls, encryption and passwords

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is a firewall?

A

A software that blocks unexpected connections coming into or out of the network.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Who deals with GDPR internally?

A

Data protection officer

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What are your individual rights under GDPR?

A
  1. Rights to informed
  2. Rights to access
  3. Rights to rectification
  4. Rights to erasure
  5. Rights ti restrict processing
  6. Right to data portability
  7. Right to object
  8. Right to automated decision making and profiling
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What are the principles of the UK GDPR?

A

States that data must be
- Processed lawfully, fairly and in a transparent manner
- Collected for specified, legitimate purposes
- Limited to what is necessary
- Data that is inaccurate/out of date mist be erased
- Kept for no longer than necessary required
- Processed in a manner that ensures appropriate security of the personal data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Who deals with GDPR externally?

A

ICO report within 72 hours

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is GDPR?

A

General Data Protection Regulation 2016 came into effect across the whole of the EU to control how personal information is used.

Now that we have left the EU, the UK’s GDPR implementation is the Data Protection Act 2018

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What are they key requirements under the Data Protection Act 2018?

A
  • An obligation to conduct data impact assessments for high risk holding of data
  • New rights for individuals to have access to information on what personal data is held and to have it erased
  • A data controller decides how and why personal data is processed and is directly responsible for GDPR
  • A new principle of data accountability ensuring that organisations can prove to the ICO how they comply with the new regulations
  • Data security breaches need to reported to the ICO within 72 hours whether there is a loss of personal data and a risk to harm to induvial
    An increase of fines up to 4% global turnover of the company or 20 million euros (whichever is highest)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is copyright?

A

A set of exclusive rights granted to the author or creator of any original work.

They can licensed, assigned or transferred

17
Q

Whats Crown Copyright?

A

all materials created and prepared for the government

18
Q

What are the exceptions from the freedom of Information Act 2000?

A
  • if the request is contrary to the GDPR requirements
  • if the request would prejudice a criminal matter
19
Q

Can you tell me about the retention of files and the Limitation Act 1980?

A

Limitation Act (1980)

Purpose is to set the time limits on various types of legal action, from this businesses can determine how long they need to keep documents
states that legal action must be brought within six years of the issue arising.
Businesses, then, have a responsibility to keep these documents for at least six years after they expire so they can refer to them if there’s a disagreement

20
Q

What is the Land Registry used for and what does a title register include?

A

Land Registry – used to access a title register which includes:

Title number
Ownership
How much the property was last sold for
Whether the property has a mortgage
Details of ‘restrictive covenants’ - promises to not do certain things with the land, like not building on a particular area
Details of any ‘easements’ - the rights of one piece of land over another, like a right of way

21
Q

What is the difference between a deed and a registered title?

A

Title refers to the ownership of a property

Deeds is the legal document that transfers title from one person to another

22
Q

What does encryption mean?

A

Encryption the process of converting information or data into a code, especially to prevent unauthorized access

23
Q

What is an Electronic Document Management System (EDMS)?

A

EDMS - An electronic document management system (EDMS) is a software system for organizing and storing different kinds of documents

24
Q

Are electronic signatures accepted by the Land Registry?

A

From July 2020 – the Land Registry will accept witnessed electronic signatures with immediate effect

25
Q

What is data redundancy?

A

Data redundancy occurs when the same piece of data exists in multiple places

26
Q

When considering if there is a personal data breach what are the factors you must consider?

A

You must consider whether there is likely to be:
- physical or material damage
- emotional distress
- embarrassment

27
Q

What is a controller?

A

A controller is defined as any entity (company or public authority) that determines the purposes and means of the processing of personal data

28
Q

What is a processor?

A

A processor is defined as any entity that processes personal data on behalf of the controller.