Data Management Flashcards

1
Q

How do you comply with UK GDPR when dealing with mailing lists?

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What sorts of information can a firm reasonably retain in order to comply with other laws?

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What data security technologies are there?

A
  1. Disk encryption
  2. Regular backups off site
  3. Password protection and use of anti-virus software protection
  4. Firewalls and disaster recovery procedures
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What systems does your firm have in place to ensure data security

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are your disaster recovery procedures

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are the acts associated with Data Management?

A

UK General Data Protection Regulation 2016 and the Data Protection Act 2018

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is the purpose of the UK General Data Protection Regulation and the Data Protection Act

A

Aims to create a single data protection regime affecting businesses, and empower individuals to take control of how their data is used by third parties
Gives people rights to be informed about how their personal information is used.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

When should data security breaches be reported to ICO

A

Within 72 hours and when there is a loss of personal data and a risk of harm to individuals

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What fines can occur if security is breached?

A

Fines up to 4% of global turnover of the company. OR £17.5 million (whichever greater)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Who polices when a security is breached

A

ICO (Information Commissioner’s Office)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What are the principles of the UK GDPR

A

Article 5(1) Principles relating to the storage of persona data states that data must be:
1. Processed lawfully, fairly and transparent manner
2. Collected for specified, explicit and legitimate purposes
3. Adequate, relevant and limited to what is necessary for the purposes for which they are processed.
4. Accurate and kept up to date
5. Processed in a manner that ensures appropriate security of personal data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What does Article 5(2) require?

A

The controller be responsible for, and able to demonstrate, compliance with the principles.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What are the 8 Individual Rights Under UK GDPR

A

Right:
1. Right to be informed
2. Right of access
3. Right to rectification
4. Right to erasure
5. Right to restrict processing
6. Right to data portability
7. Right to object
8. Rights to automated decision making and profiling

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What does the Freedom of Information Act 2000 give?

A

Gives individuals right of access to information held by public bodies

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Under the Freedom of Information Act 2000, what must be done?

A

A public body must tell any individual requesting sight of information whether it holds it
Normally public body is required to supply it in 20 working days in format requested
It can charge for the provision of the information

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What exemptions are allowed under Freedom of Information Act 2000

A

If contrary to GDPR requirements
It would prejudice a criminal matter under investigation, or a persons commercial interest

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

How can security of data be improved

A

By using firewalls, encryption and passwords
Also by understanding how non-disclosure agreement works

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

What does GDPR stand for?

A

General Data Protection Regulation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

Any other information you are aware of on Data Handling?

A

Proposed RICS Professional Statement on Data Handling and the Prevention of Cyber Crime – addresses how surveyors collect, store, and use data.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

What methods are there for securing data?

A

Digital:
* Disk encryption
* Off-site backups
* Password protection
* Anti-virus software
* Firewalls
* 2-point authentication system (phones and emails)
* Do not use US or personal email with anyone
Physical:
* Locked in filing cabinet
* Clear desk policy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

What is copyright?

A
  • A set of exclusive rights granted to the author or creator of any original work, including right to copy
  • Exclusive rights granted to creator of any work
  • A form of intellectual property
  • Can be licensed, assigned, or transferred
  • Crown Copyright – all materials prepared by Government
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

What is an NDA?

A

Legal agreement between 2 parties not to share confidential material – can be sued for damages inflicted after sharing information

21
Q

When and where do data security breaches need to be reported to?

A

To Information Commissioner’s Office within 72 hours

22
Q

What is GDPR 2018?

A

UK’s implementation of GDPR. Complete data protection system, governs personal data as well as all other data previously covered within the 1998 act. Amended 1st Jan 21 to reflect Brexit.

23
Q

What are the max fines of GDPR?

A

£17.5 million or 4% of total annual worldwide turnover in preceding financial year, whichever is higher

23
Q

When did UK GDPR come into effect?

A

New rules relating to how we collect, and process personal data came in 31 Dec 2020

24
Q

What legislation covers data protection in UK?

A

Data Protection Act 2018 and UK GDPR 2020

25
Q

Tell me what you know about GDPR?

A
  • Represents the largest change in data protection law across the EU
  • Designed to ‘harmonise’ data privacy laws across all of its members countries as well as providing greater protection and rights to individuals
25
Q

What does the Data Protection Act 2018 involve?

A

UK’s implementation of GDPR. A complete data protection system covering all general data previously covered by 1998 Act.

26
Q

What are key requirements of Data Protection Act?

A
  • An obligation to conduct data protection impact assessments for high risk holding of data
  • New rights for individuals to have access to info on what personal data is held and to have it erased
  • Data controller decides how and why personal data is processed and solely responsible for GDPR
27
Q

DPA 1998 vs DPA 2018?

A
  • Obligations more prescriptive and penalties are greater
  • Aims to create single data protection regime for business across EU and to empower individuals to take control of how data is used by third parties
28
Q

What is Article 5 of GDPR? What are the principles of GDPR?

A

-relates to processing of personal data
(a) – lawfulness, fairness and transparency
(b) – purpose limitation
(c) – data minimisation
(d) – accuracy
(e) – storage limitation
(f) – integrity and confidentiality
(g) – Accountability principle

29
Q

What are the GDPR 8 individual rights?

A

I – right to be informed
A – right of access
P – right to restrict processing
P – right to portability
E – right to erase
A – right to automated decision making and profiling
R – right to rectification
O – right to object

30
Q

Who is GDPR policed by?

A

Policed by Information Commissioners Office – can also take alternative actions instead of/as well as fines including:
1. Issuing warnings
2. Imposing a temporary or permanent ban on data processing
3. Ordering the rectification, restriction, or erasure of data
4. Suspending data transfers to third countries

31
Q

What is the Privacy and Electronic Communications Regulations (PECR) 2003?

A
  • Sits alongside the Data Protection Act and GDPR
  • Gives specific privacy rights in relation to electronic communications
  • Rules on:
    o Marketing calls, emails, texts, and faxes
    o Cookies
    o Keeping communications services secure
    o Customer privacy in regards to traffic and location data
32
Q

What is the Limitation Act 1980?

A
  • Statute that provides timescales within which action may be taken (by issuing a claim form) for breaches of the law
  • Contract – 6 years from date of negligent act. Section 14a provides alternative limitation period of 3 years from date of knowledge of the damage, subject to 15-year long stop
  • Tort – 6 years from date claimant suffered loss
33
Q

Tell me about the Freedom of Information Act 2000?

A
  • Gives the public the right to request information from public bodies in writing
  • Info has to be provided within 20 working days
  • Info will be refused in the interest of national security and current legal issues
34
Q

What is the Freedom of Information Act 2000?

A
  • Gives individuals the rights to access information held by public bodies. Required to provide the information within 20 working days.
35
Q

What are automated valuation models? What are the pros and cons?

A
  • Software systems that can provide valuations using mathematical modelling
  • Argus Val Cap, Developer
  • Cons: limited function compared to excel
  • Pros: limited mistakes
35
Q

What is ISO and what does it state?

A
  • ‘International Organisation for Standardisation’
  • International standard-setting body composed of representatives from various national standards organisations
  • Promotes worldwide proprietary, industrial, and commercial standards
36
Q

What is ISO 9001?

A
  • International Standard that specifies requirements for a Quality Management Service (QMS)
  • Requirements:
    o Monitoring and measuring equipment calibration records
    o Records of training, skills, experience, and qualifications
    o Product/service requirements review records
    o Records about designating and development outputs review
37
Q

What is Big Data?

A
  • Term that describes large volumes of data – both structured and unstructured that inundates a business on a day-to-day basis
  • Can be used and analysed for insights that lead to better decisions and strategic business moves
  • Emphasis on big data as we move to ‘smart cities’ which can identify need of the city etc
38
Q

What are Data Rooms?

A
  • Set up for property transaction, managed by lawyers / marketing team
  • Access given to relevant parties via username and password creation
  • Contains relevant information for pre-bid due diligence
39
Q

What are some data management software systems?

A
  • Excel – formula, sorting, email reminder
  • Outlook and word
  • Property and software systems – argus, RADAR, Datscha, Land Registry
40
Q

What data do you input and output?

A

Input: survey data, rental information, settlements
Output: rental information, settlements

40
Q

What are some examples of communication specific reasoned information?

A

Use of graphs, photos, evidence schedules, maps
To support arguments in tribunals, contribute to property market sentiment reports, advise on data storage/filing systems, advise on security (being young in the firm is advantage as more tech savvy than colleagues as grown up with technology), comply with client’s data security

40
Q

What is best practice in data management?

A
  • Cross reference with hard copy
  • IT system maintenance – back up
  • Protect integrity - write once, read many times
  • Info management policy, system integrity
  • Audit trail
  • Electronic signature has legal status, as long as it cannot be altered
41
Q

What are different types of data analysis?

A
  • SWOT analysis
  • Traffic light (RAG) analysis
  • Weighted analysis
  • Ranking
  • Cost benefit analysis
  • Option analysis
  • Software based or excel
42
Q

How can different data be displayed?

A
  • Graphs
  • Diagrams
  • Bar charts
  • Plotted on maps
  • Schedules
  • Tables
  • Matrices
  • Powerpoint presentations
43
Q

How does GDPR affect your firm? Compliance?

A

We are aware of where all personal data is kept. Undertake data protection impact assessments

43
Q

What is data analysis used for?

A
  • Creating shortlists
  • Creating business plans
  • Creating action plans
  • Making recommendations
  • Giving advice
  • Bringing data to life enable decisions to be made
44
Q

What is the document cycle?

A

Compose – Capture – Review – Approve – Retrieve – Archive – Compose etc

45
Q

What is the difference between a deed and a registered title?

A
  • Deeds are absolute proof
  • Registered land is a good indication
46
Q
A