Data Management Flashcards

1
Q

What are some examples of data security technologies?

A
  • Disk encryption
  • Regular backups off site
  • Password protection
  • Anti-virus software
  • Firewalls
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is copyright?

A

Exclusive rights granted to the author of any original work including the rights to copy.

Rights can be licensed, assigned or transfered.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is UK GDPR?

A

Regulations on personal data handling

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Why was the UK GDPR introduced?

A

To respond to changes to technology and the increasing use of technology.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Does the EU GDPR apply to the UK?

A

No, this was scrapped after Brexit. UK has its own GDPR (2018).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is the Data Protection Act 2018?

A

It’s the UK’s implementation of the GDPR. Controls how your personal information is used

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is the aim of the Data Protection Act 2018?

A

To create a single data protection regime for businesses and individuals to control how their data is used by 3rd parties. Gives people rights to be informed about how their personal information is used.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What are the key requirements on the Data Protection Act 2018?

A
  • Data security breaches need to be reported to the ICO within 72 hours where there is a loss of personal data or risk of harm to individuals
  • New rights for individuals to have access to what personal information is held and to have it erased
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What are the penalties of non-compliance?

A

Fines up to 4% of global turnover or £17.5 million (whichever is greater)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Who policies data protection?

A

Information Commissioners Office (ICO)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What are your rights under the Data Protection Act?

A

There are 8 individual rights under the UK GDPR:

  1. Right to be informed
  2. Right of access
  3. Right to rectification
  4. Right to erasure
  5. Right to restrict processing
  6. Right to data portability
  7. Right to object
  8. Rights to automated decision making and profiling
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What are the 7 key principles of the UK GDPR?

A

Data must be:

  1. Processed lawfully, fairly and in a transparent manner
  2. Collected for specified, explicit and legitimate purposes
  3. Adequate, relevant and limited to what is necessary
  4. Accurate and up to date
  5. Kept for no longer than necessary
  6. Kept secure
  7. The controller is accountable
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

How are you compliant with GDPR with regards to mailing lists?

A

Can only add someone to a mailing list or send marketing if they have given permission

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Other than GDPR what did the DPA 2018 introduce?

A

New offences: recklessly obtaining data, storing data without consent

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What information can a firm retain to comply with other laws?

A

ID for AML checks

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What systems does your firm have in place to ensure data security?

A

Password protected systems and files

17
Q

How would you send sensitive information?

A
  • Password protected files
  • Encryption
  • Use of firewalls and anti-virus software
  • Clear desk policy and locking away confidential documents
  • Regular change of password
18
Q

How would you deal with a data breach?

A
  • Report to the ICO within 72 hours
  • Report to my IT department
  • Inform clients and those affected
19
Q

How can you secure your own data?

A
  • Not clicking on junk / phishing emails
  • Only log on to secure wifi
  • Not sharing passwords
  • Safely dispose of personal data
  • Lock laptop away at night
  • Encrypt data
  • Use security software
20
Q

How can you send data securely?

A
  • Password protected
  • Encrypted files
21
Q

What must you do before sending marketing emails to a client?

A

Ensure that they have ‘opted in’ and provided consent.

22
Q

What is the Freedom of Information Act 2000?

A

Gives individuals the right of access to information held by public bodies.

Public body must tell the individual whether it holds the information – required to supply info within 20 days.

23
Q

What are the exemptions to the Freedom of Info Act?

A
  • Contravenes with GDPR requirements
  • Involves a criminal matter under investigation
24
Q

What is an NDA? / How does it work?

A

A binding contract between two or more parties that prevents sensitive information being shared with others. Maintains confidentiality.

25
Q

What is included in an NDA?

A
  • Name of both parties
  • Definition of what is deemed confidential
  • The term of the agreement (period of time)
26
Q

Why is it important to verify third party data?

A

Ensures accuracy and transparency

27
Q

How do you analyse data in line with GDPR?

A
  • Apply professional scepticism
  • Only base professional judgements on information I’ve verified
28
Q

How long can you keep data?

A

No longer than it is needed for the specific purpose

29
Q

What is a title document?

A

Legal document providing detailed information on a property.

30
Q

What is included on a title document?

A
  • Owner
  • Price paid
  • Tenure
  • Boundaries
  • Covenants and easements
31
Q

Is there a RICS note on data handling?

A

No, however the RICS is proposing to publish a PS on Data Handling and Prevention of Cybercrime 2019. Currently in consultation stage.

32
Q

What will the Professional Statement include?

A
  • How surveyors capture, store and share data
  • Best practices
33
Q

What is the difference between a data controller and a data processor?

A

A data controller determines the purposes and means of the processing of personal data. A processor engages in personal data processing on behalf of the controller.

34
Q

What are the fines if you don’t report a data breach to the ICO within 72 hours?

A
  • Fines up to 4% global turnover
  • OR £17.5m
  • Whichever is greater
35
Q

What kind of filing system does your company use?

A
  • Depending on what department an individual works in, we must request and get approval to the shared drive of which confidential information about clients and properties are filed on.
  • In my current line of work, data is filed in property specific folders and separated by different categories such as service charge, leases, building reports, asbestos reports etc.
36
Q

What is data triangulation?

A

Data triangulation involves using multiple data sources to confirm or refute a finding.

37
Q

What is Crown Copyright?

A

Referential material created and prepared by the Government, such as laws, public records, official press releases and OS mapping.

38
Q

Pros and Cons of Cloud storage

A