Data Management Flashcards
What are the principles of Data Protection Act (known as GDPR in the EU)
Data must be processed lawfully, fairly and in a transparent manner, collected for specified and legitimate purposes, limited to what is necessary, processed in an appropriate manner, not kept for longer than necessary, accountability
What are the rights of individuals under the Data Protection Act?
- Right to be informed
- Right of access
- Right to rectification
- Right to erasure
- Right to restrict processing
- Right to data portability (to use for their own purposes)
- Right to object
- Rights to automated decision making and profiling (as undertaken by insurance companies)
How do you ensure data security?
Password protection, firewalls, regular back-ups, anti-virus software
What is the Data Protection Act 2018?
The Data Protection Act 2018 implements GDPR 2016 into UK law and aims to create a single data protection regime
What would you do if there was a data security breach?
Inform ICO within 72 hours
What is the penalty for breaching the Data Protection Act?
4% of global turnover or £17.5 million
What is the Freedom of Information Act 2000?
Allows individuals the right to access info held by a public body, must be supplied within 20 days
What are the elements of an NDA?
Identify parties, definition of what is confidential, scope of confidentiality, length of term agreement, signatories
What does Triangulation mean?
To verify data from a third party source.
What is the ICO
Information Commissioners Office
Any RICS guidance in relation to data and data handling?
There is proposed a RICS Professional Standard on Data Handling and Prevention of Cybercrime.
How do firewalls work?
- A firewall is a system that provides security by filtering incoming and outgoing network traffic based on an organisations previously established security policies. The purpose of a firewall is to stop unwanted network communications.
What is encryption of data?
- Data encryption is a security method where information is encoded and can only be accessed or decrypted by a user with the correct encryption key.
What is a Single Sign on?
- An identity management method which enables users to log in to multiple applications and websites with one set of credentials.
If two separate departments within your firm were working for two rival companies, how would you ensure client sensitive data was managed?
- Make the clients aware of the risk including the conflict of interest
- Letter of informed consent
- Receive instruction letter to continue
- State that there would be exclusivity of staff
- NDA’s
- State the staff managing each client would be based in different working locations
- There would be single lines of communication to the client
- Secure storage of files with password protection