Data Management Flashcards
How can you ensure data security?
- Ensure that all files or written information of a confidential nature are stored in a secure manner and are only accessed by people who have a need and a right to access them
- Ensure that all files or written information of a confidential nature are not left where they can be read by unauthorised people
- Refrain from sending emails containing sensitive work-related information to their personal email address
- Check regularly on the accuracy of data being entered into computers
- Always use the passwords provided to access the computer system and not abuse them by passing them on to people who should not have them
- Use computer screen blanking to ensure that personal data is not left on screen when not in use.
What are the different types of data?
- Name, address, phone numbers - for individual and next of kin
- CVs and other information gathered during recruitment, references from former employers
- National Insurance numbers, tax codes
- Job title, job descriptions and pay grades
- Conduct issues such as letters of concern, disciplinary proceedings
- Holiday records, terms and conditions of employment, training details
- Internal performance information, sickness absence records, medical or health information
How does GDPR affect your daily role?
- Requires me to ensure that all personal data is processed lawfully and for its intended purpose
- Client or tenant information is kept confidential and stored in secure, password-protected files.
- Responsible for ensuring that data is accurate, up-to-date, and only accessible by authorised personnel in compliance with the Data Protection Act 2018
How does your company keep client information confidential and secure?
- Password-protected files and restricted access for sensitive data
- Encryption for digital files and communication
- Regular data audits and backups to ensure data integrity and prevent loss
- Multi-factor Authentication
- Ensuring staff are trained in GDPR and data protection best practices
In your example, how did you analyse the comparable data for the valuation?
Verifying each data point with agents and individuals to ensure accuracy
Cross-referencing the information with market trends and local conditions to ensure it was relevant and up to date
Organising the data into a comparable evidence schedule, ensuring it was clear and easy to interpret for the purposes of the valuation
How did you implement a systematic approach to data management at Basildon Council?
- By creating a standardised template for property inspection reports
- Ensured consistency in data collection and reporting
- Also set up regular audits to verify the accuracy of the data and address and discrepancies
In your Basildon example, what did the standardised template contain?
Included:
- Property details: Address, type, and key features
- Inspection dates and purpose and inspector details
- Sections for building condition, defects identified, and repair recommendations
- Photographs and site notes for consistency and detail
What is the importance of having accurate and up-to-date data?
- Supports informed decision-making for valuations, property management, and lease negotiations
- Ensures compliance with legal obligations and client requirements
- Helps to maintain trust with clients, knowing that decisions are based on reliable and current information
- Reduces the risk of errors, which could impact property valuations or legal obligations
How do you verify data when collecting it for professional purposes?
- Cross-referencing it with multiple sources, such as internal records, agents, or official documents
- Directly contacting individuals involved in the transactions to confirm key details
- Checking for consistency and ensuring the data aligns with current market conditions
What key principles of data management do you follow in your practice?
- Accuracy and reliability: Ensuring data is correct and up-to-date
- Confidentiality and security: Protecting sensitive information through encryption and restricted access
- Verification: Cross-checking information from multiple sources to confirm accuracy
- Compliance: Following GDPR and Data Protection Act 2018 guidelines to manage and store data lawfully
What would you do if there was a breach of data?
- Immediately report it to the DPO or the person responsible for data compliance within the company
- Notify insurers
- Contain the breach by securing the data and preventing further unauthorised access
- Document the breach: Record details of the breach, how it occurred, the data involved, and any actions taken to mitigate damage
- Follow company procedures for investigating and responding to the breach
Who would you report data breaches to?
- The Data Protection Officer within my organisation
- If the breach poses a risk to individuals’ rights or freedoms, the Information Commissioner’s Office (ICO) must be notified within 72 hours of becoming aware of the breach
What is your company’s procedure for handling data breaches?
- Immediate internal reporting of the breach to the DPO
- Containment and mitigation to prevent further loss or unauthorised access to data
- Investigation into the cause and extent of the breach
- Notification to the ICO if the breach poses a risk to individuals’ rights or freedoms, and, where required, notify affected individuals
- Documentation of the breach and actions taken to prevent recurrence
What is the Data Protection Act 2018 and GDPR?
The DPA 2018 is the UK’s implementation of the General Data Protection Regulation (GDPR).
Governs how personal data is handled, ensuring it is processed lawfully, transparently, and securely
GDPR provides the framework for data protection across the EU, and DPA 2018 adapts this to the UK’s legal context post-Brexit
What are the key requirements of the DPA 2018 and GDPR?
- Lawful Processing: Personal data must be processed lawfully, fairly, and transparently
- Purpose Limitation: Data should only be collected for specified, explicit, and legitimate purposes
- Data Minimisation: Collect only the data necessary for the purpose
- Accuracy: Keep data accurate and up to date
- Storage Limitation: Data should not be kept longer than necessary
- Security: Ensure appropriate security to protect data from breaches