Data Management Flashcards

1
Q

What is GDPR?

A

General Data Protection Regulation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is the purpose of GDPR?

A

Protect citizens personal data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What constitutes personal data?

A

Any information related to a person or ‘Data Subject’ that can be used to identify a person EG names, photo, email address, bank details etc

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Examples of personal data under GDPR that could apply to property companies?

A

Investor information, employee information, marketing, tenant, client information.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

To what organisations does GDPR apply?

A

All organisations of more that 250 employees

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What are penalties for GDPR breaches?

A

4% of annual global turnover or up to 20 million euros.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is the ‘right to access’ under GDPR? How would they do this?

A

Individuals have the right to obtain confirmation that their data is being processed, and access to their personal data

Through a SAR or Special Access request under Article 15 of of the UK GDPR Act. An individual can request a company provides any information a company holds on that person. The SAR does not have to be formally stated, it can be verbally or in writing or even on social media.

If someone makes a SAR, consult the Workman compliance team on the next steps. You can clarify the request and you can withhold information under certain reasonable grounds which must be stated.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is a breach notification under GDPR?

A

Need to report within 72 hours of becoming aware of breach

If breach high risk, then need to notify individual without delay

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

How are data breaches typically discovered?

A

Access logs, reported thefts, lost equipment or data security incident, technology/systems audits

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

How have consent conditions been strengthened under GDPR?

A

Consent must be given using plain and clear language

Must be as easy to withdraw consent as it is to give it

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is ‘right to be forgotten’ under GDPR?

A

Under Article 17 of GDPR, individuals have right to have personal data erased in certain circumstances

Data no longer necessary

Data been processed unlawfully

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is data portability?

A

Under Article 20 - Right for data subject to receive personal data concerning them which they have previously provided, and have it transmitted to another controller

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is privacy by design?

A

Legal requirement under GDPR

Calls for inclusion of data protection from onset of designing systems, rather than as addition

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is data protection officer?

A

An individual appointed to monitor internal compliance and advise on an organisations data protection obligations

Only required if organisation is public body, authority or carrying out certain type of processing activity

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Examples of data held by surveying practices?

A

Payroll and HR

Customer data for marketing

Emails and correspondence relating to clients and employees

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What are obligations imposed by GDPR?

A

Must have knowledge of data you store and process

Need to be able to provide information on how data is used and the rights of individuals regarding their data

Need to be able to demonstrate data is being managed in compliant manner

Must be able to delete every instance of an individuals data in compliance with ‘right to be forgotten’

Must keep data in format that allows portability to another data processor, should the need arise

Data must be securely stored with sufficient access controls and encryption where necessary

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

Who regulates GDPR in the UK?

A

Information Commissioners Office - ICO

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

RICS best practice points for complying with GDPR? How does Workman compl

A

Conduct data review

Anonymise data where possible

Encrypt everything where possible

Treat commercial data in same way as personal data, even though not covered by GDPR

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

What are your companys policies for data protection breaches?

A

Report to line manager or Data Protection Officer/compliance team within the firm

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

RICS recommendations for using confidential information?

A

Document purposes for which you are allowed to hold information

Keep record of consent for processing, storage and retention

Check if you have appropriate contractual clauses for use of information

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

What information should be included in firms privacy notice?

A

What information you have

What the information will be used for

Which third parties information will be shared with

How long information will be stored for

What legal rights they have

22
Q

When did GDPR come into effect under the Data Protection Act 2018?

A

May 2018

23
Q

What are the 7 principles of Data Protection Act 2018? (AKA 7 principles of GDPR)

A

Lawfulness, fairness, transparency

Accuracy

Accountability

Purpose limitation

Storage limitation

Data minimisation

Integrity and confidentiality

24
Q

8 individual rights under GDPR?

A

Right to Information

Right to Access

Right to Rectification

Right to Erasure

Right to Restrict Processing

Right to Data Portability

Right to Object

Right to Automated Decision Making

25
Q

What was the Freedom of Information Act?

A

Came into effect in 2000

Allows an individual to request access to information held by a public body

Public body is required to provide that information (within 20 working days) in requested format

They can charge a fee for this

26
Q

What are the provisions of the Land Registry Act (2002)?

A

Provides a complete and accurate reflection of the state of the title of the land at any given time

Aim is to get all freehold land in England and Wales registered by 2030

27
Q

Disadvantages of the systems you use?

A

Rely on data input completed by others - human error

External systems - firm is not in control of security

Not user friendly and lots of staff training required!

28
Q

How do you comply with GDPR in your role? 

A

Don’t forward on email chains

Don’t share passwords or log ins

Wouldn’t sent an email to more than one tenant copied in, BCC.

29
Q

Give me an example of how you ensure that data is kept securely.?

A

Strong password protection

Firewall

Anti-virus software

30
Q

What is copyright? 

A

The exclusive and assignable legal right given to the originator for a fixed number of years, to print, perform, film or record literacy, artistic or musical material. 

31
Q

What does block chain mean?

A

Shared ledger system that facilitates process of recording transactions across a computer network

32
Q

What are the obligations under GDPR?

A

Need to have knowledge of data held and processed
Have the ability to delete data every instance of data on subject
Demonstrate data management compliance
Prove how data is used
Prove data portability (allow subject to reuse personal data for own purpose)

33
Q

Explain the growing use of AVMs in the industry?

A

Automated valuation models

  • Speed, cost and removal of human errors
  • Issue is that prop isnt inspected and lack of comparable data
34
Q

Can you give me some examples of reports that you run?

A

Arrears report
Tenancy schedules
Service charge analysis

35
Q

What is a firewall?

A

Computer network security system that restricts internet traffic

36
Q

Which records are manually kept in your office and why?

A

Financial records e.g. invoices and receipts - In case the system ever goes down

37
Q

Who is exempt from GDPR?

A

National security
Journalism (In some circumstances)
Law enforcement
Academic research
Public health

Each of these organisations have their own rules to follow

38
Q

Can you tell me how CCTV relates to GDPR and the principles that underpin it?

A

Data transparency - Lawful/fair
Purpose limitation - requires personal data to be collected
Storage limitation - Only retained for time period
Secured against unauthorised access - data controller etc

39
Q

How do you access and use your Data Management systems, such as HORIZON

A

Property Management System eg Horizon
1) Encrypted login
2) Two factor authentication
3) Search up property on system - go to data source needed e.g. invoice

40
Q

What is an electronic document management system?

A

Workman use EFS - Electronic Filing System

41
Q

What are the limitations of secondary data sources?

A

No control on what is contained in data
Lack of confidence could be wrong and inaccurate - validity
above link to GDPR

42
Q

How do you comply with GDPR in your role?

A

Report breaches
Do not give out personal info
Keep records of data consent
Ensure info held is in line with GDPR

43
Q

Can you tell me about the retention of files and limitations act 1980?

A

Sets out how long business should keep documents
for. States legal action must be brought within 6 years of issue arising

44
Q

What is BIM and how can it be used?

A

Building information modelling
- Generate and manage digital representations of elements of a building e.g. project planning and historic preservation

45
Q

Explain how the H&S updates you make ensure you can monitor compliance on Meridian and Quooda?

A

Time stamped record of actions completed and comments made as well as who made them

See when risk assessments run out - Instruct

46
Q

Can intellectual property be transferred?

A

Yes - Written agreement e.g. contract/assignment

47
Q

What are CPSES?

A

Commercial Property Standard Enquiries

48
Q

What constitutes personal data?

A

Any info relating to identified person

49
Q

How is data managed on the Tramps (Horizon + Sharepoint) platform?

A

Collaboration and sharing between different teams
within businesses (and between business)

Only authorised users can access certain files

Audit trails document activity

50
Q

How does your firm ensure property management systems are correct?

A

Property managers can view certain information on the property management system but they cannot alter anything

For any changes, they must submit a data input form which must be signed off by an associate or higher. The data input controllers can only input what is on the forms.

Client accountants can make some changes to the property management system but most changes require the data input controllers

Any changes have a digital receipt which shows who made a change and when.

51
Q

How does Workman ensure confidential information is kept secure?

A

The compliance team operate a red, amber, green system.

Red - document is marked as confidential and cannot be shared externally or edited

Amber - Internal firm wide documents eg detailing Workman policy - only Workman user accounts may access them and they will be rejected if shared to external recipients. Workman used Azure Information Protection (AIP) to track and encrypt documents

Green - Documents can be shared freely

52
Q
A