DATA MANAGEMENT Flashcards
How was GDPR affected you in the office?
In job role – right to collect something we actively do at check and in form of return where personal data is collected. Making sure I store data security – naming conventions, locking laptop and not leaving un attended. Passwords in to laptop and two factor authentications.
You mention GDPR 2018, when did UKGDPR come into force?
2020
What are the principles under the UK GDPR 2018
Article 5 principles relation to the storage of personal data states that data must be:
Lawfulness, fairness and transparenct - Processed lawfully, fairly and in a transparent manner in relation to individuals
Purpose limitation - Collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes
Data minimisation - Adequate, relevant and limited to what is necessary for the purposes for which they are processed
Accuracy - Accurate and where necessary kept up to date every reasonable step must be taken to ensure that personal data that are inaccurate having regard to the purposes for which they are processed, are erased or rectified without delay
Storage limiation - Kept in a form which permits identification of data subject for no longer than is necessary for the purposes for which the personal data are processed
Intergrity and confidentiality - Processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures
Accountability - Article 5 requires that “the controller shall be responsible for, and be able to demonstrate, compliance with the principles”
What is special category data
Special category data can be factual or inferred information about an individual. If you are intentionally processing data to infer details that fall within the special categories of data such as a person’s ethnic origin or political opinions then this is considered special category data.
What is a subject access request
A SAR is a request made by or on behalf of an individual for the information which they are entitled to ask for under Article 15 of the UK GDPR.
What penalties are there if data breach under the CRCA?
Maximum penalty of two years imprisonment, a unlimited fine or both.
Are there any alternative actions – other than fine what can they do?
warning, temporary or permanent band on data processing
What is the freedom of information act?
Provides public access to information held by public authorities.
What information is exempt from freedom of information?
Personal data and national security
On the SDLT exercise, who were you advising?
I advised senior colleagues on the most reliable data which in turn would support the valuation work they undertake.
SDLT -How did they access the information you collated?
They accessed the information through our internal database. Password proected.
This geospatial commission group, are they part of HMRC?
Yes
Are we going to give them our rental values to put onto the data mapping system?
I suggested recommendations of how the process of CCA could be inputted into mapping.
Geospation - You fed back your findings, how did you present the evidence?
PowerPoint presentation which I presented in a meeting.
Did they ask questions?
The Geospatial commission had the chance to ask questions at the end of the presentation.
What happens if there is a data breach?
When a breach involves personal data we must act quickly to assess any potential impacts to the individual. If deemed necessary, we have just 72 hours from th discovery of data breach to report it to the Information Commissioners Office (ICO).
Data file retention policies?
Minimum 6 years as this is length of time sued for negligence, there are way os suing after this time.
Used to dispose of paper after 6 and move electronically
Our only data base tends to keep the data, we have data from 2012. Can have affect on future decisions or can retain helpful information.
Within the VOA we have retention schedules that set out the agreed retention period for all different types of information depending on the business area.
If identified for disposal on the agency retention schedule then can dispose of information.If it isn’t then have to have approval from Information Asset Owner to destroy.
Was it all sales on SDLT?
No just land sales
I can see you provided about which transactions are reliable, how did you advise which were not reliable?
Those with connected parties, the consideration
How did you identify which ones are connected parties?
On the transaction can see who the vendor and purchaser was looking at their names to see if same surnames, further checks on companies house to see if transferred between businesses
How did you analyse development land sales?
I had regard to whether planning application had been made on the site
If had planning granted how did you analyse these?
Put a comment against the transaction, if there was permission, no planning, or hope value
Did you analyse the figures in more detail, price per hectare/acre?
Analysis on a price per acre
How would you identify amenity land?
Rough land, less than 5 acres, woodland or rivers close by