Data Management Flashcards

1
Q

What is the distinction between the Data Protection Act, 2018 and UK GDPR?

A

The EU GDPR no longer applies in the UK but this was almost entirely transcribed in the UK GDPR
The UK GDPR is supplemented by the Data Protection Act 2018.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is the aim of this legislation?

A

To create a single data protection regime affecting businesses and to allow people to take control of how their data is used by third parties

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are the key requirements of the Data Protection Act?

A
  • An obligation to conduct data protection impact assessments for high risk holding of data
  • A data controller decides how and why personal data is processed and is directly responsible for GDPR
  • Data security breaches need to be reported to ICO within 72 hours where this is a loss of personal data
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are the fines for breach of this legislation?

A

4% Global turnover or £17.5 million, whatever is greater

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are the principles of UK GDPR?

A

Article 5(1) Principles relating to the storage of personal data must …
- Be processed lawfully, fairly and in a transparent manner
- Collected for specified, explicit and legitimate purposes
- Ensure appropriate security of data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is personal data?

A

Any data that identifies a person, e.g. name, address, date of birth

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

How would you ensure accuracy of data from third parties?

A

When sourcing data from third parties such as CoStar, I always call the relevant agents to confirm accuracy in the data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

How do you ensure appropriate data protection on the Cluttons portal?

A
  • The portal requires users to update passwords every 30 days
  • Access is restricted to the requirements of each user.
  • All accounts have to be approved by the client
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

How did your firm prepare for the introduction of GDPR?

A

Data training, cyber security training, password requirements

How well did you know this?
1
Not at all
2
3
4
5
Perfectly