Data Management Flashcards
What data sources do you frequently use?
CarboniCa, EPDs and LCAs, PST
What systems do you use to store data?
CarboniCa, SharePoint, Teams, Excel, Concur, Eric
Techniques or methodologies most appropriate to collect and store data:
EPDs stored in a spreadsheet, CarboniCa logic in Excel, manually collecting BNG data for our central tracker
Importance of verifying data through triangulation
What is the Data Protection Act 2018?
The 2018 Act replaces the 1998 Data Protection Act and relates to personal data. The Act creates a single data protection regime which affects businesses and empowers individuals to take control of how their data is used by third parties. Similar to EU law.
What are the key requirements for the Data Protection Act 2018?
- Obligation on data collectors to conduct data protection impact assessments for high risk holding of data
- New rights for individuals to have access to information on what personal data is held and to have it erased
- New principle of ‘data accountability’ ensuring that organisations comply with the new regulations and they must prove this to the ICO
- Data breaches must be reported to the ICO within 72 hours when there is loss of personal data
- Fines can be up to 4% of the global turnover of a company who have not complied (or £17.5m – whichever is higher)
- The ICO police this
What is UK General Data Protection Regulation (GDPR)?
GDPR enhances the current data protection regulations and means that for personal data, informed consent must be obtained, all data processing must be in accordance with ‘privacy by design’ and personal data can only be collected for specific legitimate purposes.
What is personal data under the GDPR?
Defined by Article 4(1) of the GDPR, personal information is defined as being ‘identifiable’ e.g. a name, number, location data or other online identifiable like IP address
What could happen if GDPR is not adhered to?
If GDPR is not adhered to, reputational damage can occur, as well as damage to the research process, distress to individuals or harm to personal safety, substantial financial or legal punitive penalties
Implications of GDPR for children?
GDPR for children is anyone under the age of 18.
GDPR enhances the protection of children’s data and ensures children are addressed in plain clear language – safeguarding issue for.
Data Protection Impact Assessment (DPIA) can be used for children to mitigation data protection risks to the child
Key principals of GDPR
- Personal data must be stored lawfully, fairly and in a transparent way for individuals
- Collected or specified purposes and not further processed for something beyond that purpose
- Data limited to the purposes for which they are processed
- Taking all steps to keep personal data up to date; if out of date, it should be erased or rectified
- Kept in a format which only allows individuals to be identified for the purpose in which the data was collected
- Data is processed in a manner which ensures appropriate security of personal data, including protection from unlawful processing
- Section 5(2) requires that the controller is responsible for compliance of the principles and should be able to demonstrate these
What are an individual’s rights under GDPR?
- Right to be informed
- Right of access
- Right to rectification
- Right to erase
- Right to restrict processing
- Right to data portability (use the data for their own purposes)
- Right to object
- Rights to automated decision making and profiling
Tell us about how you comply with GDPR in your role?
Collecting personal email addresses to give the participants access to CarboniCa. Individually provided by email after I gave them informed consent regarding the project:
- Understand the scope of the project and why their email address was needed
o They only have the accounts for 3 months then they are deleted with all of the personal data too - Provision to sign them up to CarboniCa with MSES
- At any point they could remove themselves from the study and leave CarboniCa
How do you align yourself to ISO 27001?
Updated in 2022 - MSC working to re-align but aligned to 2013 model, gap analysis done by MSG
MSC Information Management System is aligned
What is ISO 27001?
ISO 27001 is an international standard to manage information securely. It specifies the requirements for establishing, implementing, maintaining and improving an information security management system within the context of an organisation. This framework requires organisations to identify information security risks and select appropriate controls to tackle them.
What is IP?
Intellectual property (IP) is a category of property which you create using your mind. Example types include copyrights, trademarks, and patents.
What would happen if IP were breached?
Violation of IP laws may be a breach of civil or criminal law, depending on the type of IP.
CarboniCa has IP which must be protected. This is written into a collaboration agreement with NTU. We offer license only under a non-disclosure agreement (NDA) with Circular Ecology and NTU.
What is copyright?
Copyright refers to a set of exclusive rights to the author of particular work, including the right to copy. It is a form of IP
o These rights can be licensed or transferred
* Crown Copyright is anything created by or prepared by the Government, such as laws, public records, OS mapping
* Copyrights within work must be acknowledged
What is informed consent?
Informed consent is at a minimum, that the participant understands what the research is and what they are consenting to. They should never be pressured, and this should be before the research begins
For our Innovate UK project with NTU, we gathered written consent from all participants. I provided them with a brief on the project and gave ample time for consent replies. I used NTU written consent template as this was familiar to them and understandable to the participants
How is data securely stored?
Password protected EPD spreadsheet to avoid human error, controlling access
Encrypted ‘data at rest’ - need to log back in to view or edit
In two places to avoid deleting
Did read online that the RICS are planning to release a Data Handling and Prevention of Cybercrime Professional Statement. It is proposed that this will cover how surveyors capture, store and share data – mandated for all firms and members
MSG use ‘Prevalent’ which is a 3rd party risk management system e.g. GAIA
What is an NDA?
A non-disclosure agreement is an understanding of a confidential relationship between parties, typically to protect any type of confidential information.