Data management Flashcards
What act governs Data?
The Data Protection Act 2018
What are the 6 data protection principles under the data protection act 2018?
Everyone responsible for using data must ensure the data is:
- Used fairly, lawfully, and transparently
- Used for specified, explicit reasons
- Used in a way that is adequate, relevant, and limited to only what is necessary
- Accurate and, where necessary, kept up to date
- Kept for no longer than is necessary
- Handled in a way that ensures appropriate security, including protection against unlawful or unauthorised processing, access, loss, destruction or damage
How long should you keep data for in construction?
- 6 years if contract signed under hand
- 12 years if under deed
- RICS recommends up to 15 years, this is the limitation period for most legal claims
What is the maximum penalty for a breach in GDPR?
€20 million, or 4% of the previous years global annual turnover, whichever is higher
What must you do if you accidentally breach GDPR?
Report to your data protection officer who will then report it to ICO (information Commissioner’s Office) regulator
What does GDPR stand for?
General Data Protection Regulation
What is meta data?
Information about a specified piece of data e.g. the author, file size, when it was created
What are your rights under The Data Protection Act 2018?
- The right to be informed.
- The right of access.
- The right of rectification.
- The right to erasure.
- The right to restrict processing.
- The right to data portability.
- The right to object.
- Rights of automated decision making and profiling.
- Diversity, Inclusion & Team Working
What data do you use day-to-day?
- Cost Plans
- Tenders
- Valuations
- Cost Reports/Company Budgets
- Contract Documentation
- Emails/Private Correspondence
How do you ensure compliance with GDPR?
- Ensuring any printed information is locked away securely
- Locking my laptop when away from my desk, and ensuring it is safe when out of the office/home
- Using password protection/access restrictions to data where necessary
- Marking information as confidential when sending to ensure it is not accidentally forwarded on.