Data Management Flashcards
What is GDPR?
General Data Protection Regulation
What is the purpose of GDPR?
Protect citizens personal data
What constitutes personal data?
Any information related to a person or ‘Data Subject’ that can be used to identify a person EG names, photo, email address, bank details etc
Examples of personal data under GDPR that could apply to property companies?
Investor information, employee information, marketing, tenant, client information.
To what organisations does GDPR apply?
All organisations of more that 250 employees
What are penalties for GDPR breaches?
4% of annual global turnover or up to 20 million euros.
What is the ‘right to access’ under GDPR? How would they do this?
Individuals have the right to obtain confirmation that their data is being processed, and access to their personal data
Through a SAR or Special Access request under Article 15 of of the UK GDPR Act. An individual can request a company provides any information a company holds on that person. The SAR does not have to be formally stated, it can be verbally or in writing or even on social media.
If someone makes a SAR, consult the Workman compliance team on the next steps. You can clarify the request and you can withhold information under certain reasonable grounds which must be stated.
What is a breach notification under GDPR?
Need to report within 72 hours of becoming aware of breach
If breach high risk, then need to notify individual without delay
How are data breaches typically discovered?
Access logs, reported thefts, lost equipment or data security incident, technology/systems audits
How have consent conditions been strengthened under GDPR?
Consent must be given using plain and clear language
Must be as easy to withdraw consent as it is to give it
What is ‘right to be forgotten’ under GDPR?
Under Article 17 of GDPR, individuals have right to have personal data erased in certain circumstances
Data no longer necessary
Data been processed unlawfully
What is data portability?
Under Article 20 - Right for data subject to receive personal data concerning them which they have previously provided, and have it transmitted to another controller
What is privacy by design?
Legal requirement under GDPR
Calls for inclusion of data protection from onset of designing systems, rather than as addition
What is data protection officer?
An individual appointed to monitor internal compliance and advise on an organisations data protection obligations
Only required if organisation is public body, authority or carrying out certain type of processing activity
Examples of data held by surveying practices?
Payroll and HR
Customer data for marketing
Emails and correspondence relating to clients and employees
What are obligations imposed by GDPR?
Must have knowledge of data you store and process
Need to be able to provide information on how data is used and the rights of individuals regarding their data
Need to be able to demonstrate data is being managed in compliant manner
Must be able to delete every instance of an individuals data in compliance with ‘right to be forgotten’
Must keep data in format that allows portability to another data processor, should the need arise
Data must be securely stored with sufficient access controls and encryption where necessary
Who regulates GDPR in the UK?
Information Commissioners Office - ICO
RICS best practice points for complying with GDPR? How does Workman compl
Conduct data review
Anonymise data where possible
Encrypt everything where possible
Treat commercial data in same way as personal data, even though not covered by GDPR
What are your companys policies for data protection breaches?
Report to line manager or Data Protection Officer/compliance team within the firm
RICS recommendations for using confidential information?
Document purposes for which you are allowed to hold information
Keep record of consent for processing, storage and retention
Check if you have appropriate contractual clauses for use of information