Data Management Flashcards

1
Q

How is Lendlease compliant with UK GDPR?

A

Lendlease has a ‘Data Governance Forum’ whereby members take leadership for data sets which are high value e.g.

  • Privacy Council manage personal data
  • Verification Committee ensure what is communicated externally is accurate, they ‘fact check’

We undertake training on:
- Storing data - who can access this data? Is this a LL or third party store? Is there disaster recovery?
- Processing data - only process data in ways that are consistent with the purpose it was obtained for / how the accuracy of data / access control during processing
- Sharing data - do you know the rights we have for sharing the data? Is it on a need to know basis? Has it been validated if going public?
- Destroying data - Only keep for as long as needed / can personal data be de-identified / security and protection of records and archives

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What data do you use in your role?

A

A range of data for different purposes:

  • Budgets
  • Development appraisals
  • Info from architects (drawings / models / schedules)
  • Comparable evidence / market evidence (Molior - reliant on developers uploading)
  • Agents (reports - pretty reliable)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is a useful trigger for important data collection dates?

A

Diaries

  • Rent collection
  • Rent review notices
  • Insurance renewals
  • Regular inspections
  • Repairing obligations
  • Break clauses
  • Planning obligations
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is triangulation?

A

Verifying data against an alternative source

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What do data security technologies include?

A
  • Disk encryption
  • Regular backups off site
  • Cloud storage
  • Password protection
  • Anti-virus protection
  • Firewalls
  • Disaster recovery
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is copyright?

A
  • Set of exclusive rights granted to the author / creator of original work, including right to copy
  • Rights can be licensed, assigned or transferred
  • Form of intellectual property
  • Crown copyright (all material prepared by Gov like laws, public records, press releases, OS mapping)
  • Must acknowledge copyright in your work
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is the key legislation regarding data protection in the UK?

A

Data Protection Act (2018)
UK General Data Protection Regulation and the Data Protection Act (2018)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is the purpose of UK GDPR?

A
  • Single data protection regime
  • Affects businesses, with the goal to empower individuals to control how their data is used by third parties
  • Right to be informed how data is used
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What are the requirements of UK GDPR?

A
  • Data protection impact assessment for high risk holding of data
  • Rights for individuals to have access to personal info held and have it erased
  • Data controller decides how and why data is processed and responsible
  • ‘Data accountability’ ensures firms can prove to the ICO (Information Commissioner’s Office) how they comply with regs)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is the penalty for security breaches?

A
  • Breaches must be reported to ICO within 72 hours where there is a loss of personal data and risk of harm
  • Fine of 4% turnover, or £17.5 million (whatever is greater)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Who polices UK GDPR?

A

Information Commissioner’s Officer

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What are the principles of UK GDPR?

A

Article 51:

  • Process lawfully and transparently
  • Collect for specified and legit reasons
  • Limited to what is necessary
  • Accurate and kept updated
  • Kept in a form which permits identification
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What are individual rights under UK GDPR?

A
  • Right to be informed
  • Right of access
  • Right to rectification
  • Right to erasure
  • Right to restrict processing
  • Right to object
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What legislation gives individuals right of access to information held by public bodies?

A

Freedom of Information Act (2000)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What does the Freedom of Information Act (2000) set out?

A
  • Public body must tell any individual requesting the info if it holds it
  • Required to supply info in 20 days
  • It can charge

Exemption: If it would prejudice a criminal matter under investigation, or a persons/firms commercial interest

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Is there anything emerging on cybercrime?

A

Proposed RICS Professional Standard on Data Handling and Prevention of Cybercrime

  • Best practise
  • Mandatory obligations
  • How surveyors must capture, store and share data appropriately
17
Q

What is an NDA?

A
  • Legally enforceable contract between a person with sensitive information and a person with access to that information
  • If breached, take legal action and seek damages for losses incurred
18
Q

When do you use data management in your role?

A

ACC - Store and share the most recent information between the design team. Have to be given special permission by LL to access it.

Contractor records
Contract records
Photos
Health records

19
Q

What data do you need? What do you need the data for? What is the data source? What format is the data? Can you verify the data is accurate?

A

Design info from consultants
Market info from agents / Molior

20
Q

What are you going to do with the data? Method of analysis / methodology?

A

Submit it for planning
Use it to inform further design
Use it to position products

21
Q

How will you present data?

A

Baked into design
Presented in a presentation / report

22
Q

What is Lendlease’s policy on data storing / how long can you store it for before it has to be erased?

A
23
Q

What is key legislation?

A

Data Protection Act (2018)

  • Controls how your data is used by organisations and the government
  • UK’s implementation of GDPR (EU initative that was readopted after Brexit into the Data Protection Act). Under GDPR, implemented by the Data Protection Act (2018):
  • Data protection principles (used fairly, lawfully, transparently, adequate, relevant and limited, specified purposes, up to date, kept no longer than necessary, stored properly)
  • Strong data protection on genetics, religion, health, sexual orientation, criminal conviction
  • You have right to see how data is being used (informed, access, corrected, erased, object, up to date)