Data Management Flashcards
What data security technologies are there?
- Disk encryption
- Regular backups off site
- Password protection and use of anti-virus software protection
- Firewalls and disaster recovery procedures
What are the acts associated with Data Management?
UK General Data Protection Regulation 2016 and the Data Protection Act 2018
What is the purpose of the UK General Data Protection Regulation and the Data Protection Act
Aims to create a single data protection regime affecting businesses, and empower individuals to take control of how their data is used by third parties
Gives people rights to be informed about how their personal information is used.
When should data security breaches be reported to ICO
Within 72 hours and when there is a loss of personal data and a risk of harm to individuals
What fines can occur if security is breached?
Fines up to 4% of global turnover of the company. OR £17.5 million (whichever greater)
Who polices when a security is breached
ICO (Information Commissioner’s Office)
What are the principles of the UK GDPR
Article 5(1) Principles relating to the storage of persona data states that data must be:
1. Processed lawfully, fairly and transparent manner
2. Collected for specified, explicit and legitimate purposes
3. Adequate, relevant and limited to what is necessary for the purposes for which they are processed.
4. Accurate and kept up to date
5. Processed in a manner that ensures appropriate security of personal data
What does Article 5(2) require?
The controller be responsible for, and able to demonstrate, compliance with the principles.
What are the 8 Individual Rights Under UK GDPR
Right:
1. Right to be informed
2. Right of access
3. Right to rectification
4. Right to erasure
5. Right to restrict processing
6. Right to data portability
7. Right to object
8. Rights to automated decision making and profiling
What does the Freedom of Information Act 2000 give?
Gives individuals right of access to information held by public bodies
Under the Freedom of Information Act 2000, what must be done?
A public body must tell any individual requesting sight of information whether it holds it
Normally public body is required to supply it in 20 working days in format requested
It can charge for the provision of the information
What exemptions are allowed under Freedom of Information Act 2000
If contrary to GDPR requirements
It would prejudice a criminal matter under investigation, or a persons commercial interest
How can security of data be improved
By using firewalls, encryption and passwords
Also by understanding how non-disclosure agreement works
What does GDPR stand for?
General Data Protection Regulation
Any other documenatation you are aware of on Data Handling?
Proposed RICS Professional Statement on Data Handling and the Prevention of Cyber Crime – addresses how surveyors collect, store, and use data.
What methods are there for securing data?
Digital:
* Disk encryption
* Off-site backups
* Password protection
* Anti-virus software
* Firewalls
* 2-point authentication system (phones and emails)
* Do not use US or personal email with anyone
Physical:
* Locked in filing cabinet
* Clear desk policy
What is copyright?
- A set of exclusive rights granted to the author or creator of any original work, including right to copy
- Exclusive rights granted to creator of any work
- A form of intellectual property
- Can be licensed, assigned, or transferred
- Crown Copyright – all materials prepared by Government
What is an NDA?
Legal agreement between 2 parties not to share confidential material – can be sued for damages inflicted after sharing information
When and where do data security breaches need to be reported to?
To Information Commissioner’s Office within 72 hours
What is UK GDPR 2016?
UK’s implementation of GDPR. Complete data protection system, governs personal data as well as all other data previously covered within the 1998 act. Amended 1st Jan 21 to reflect Brexit.