Data Management Flashcards

1
Q

How long should old files be held for on a client

A

6 years before securely disposed of

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is the purpose of GDPR

A

Protect citizens personal data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What constitutes personal data

A

Any information relating to a person that can be used to identify them

Such as name, photos, email address, bank details

Examaples used in the property industry
Investor data
Valuation
Background checks by HR
Compliance checks

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Data security technologies

A

Fire wall and disaster recovery procedures

Password protection and use of anti-virus systems

Regular back ups off site

Disk encryption

… Essential that data is kept safe from corruption and access is suitably controlled. Ensuring privacy and protection

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What legislation are you familiar with regarding data management

A

Uk GDPR 2016 and data protection act 2018

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Who is responsible for GDPR and how and why personal data is used

A

The data controller

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Who do you report a data breach too

A

The information commissioners office ICO Within 72 hours

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Individual rights under GDPR

A

Rights to be informed
Access
Rectification
Erasure
Restrict processing
Data portability
Object

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Freedom of information act 2000

A

Gives individuals the right of access to any info held by public bodies

Exceptions include criminal matters under investigation and commercially sensitive info

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

7 key principals of data storage UK GDPR

A

Lawfullness, fairness and transparency- process data legally openly and honestly

Purpose limitation- use data for clearly defined purposes

Data minimisation- collect only what’s necessary

Accuracy

Storage limitation

Integrity and confidentiality- protect from breaches

Accountability

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Give an example of how Bradley hall prevents data breaches

A

We have password protected files and when working from home and signing in from a seperate internet connection we need to connect to the Bradley hall vpn

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What information requires further security

A

Health records and bank details

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What are the UK GDPR Regulations

A

The UK GDPR (General Data Protection Regulation) sets rules for processing personal data in the UK.

It is set out by showing

Data protection principals

Lawful bases for processing

Rights of data subjects

Accountability and governance

Security of processing

Data breaches

Penalties for non compliance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What are the RICS guidelines on data storage

A

Confidentiality: Ensure all client and project data is securely stored and accessible only to authorized personnel.

Compliance: Adhere to relevant data protection laws (e.g., GDPR) and industry standards for secure storage and management.

Accuracy and Integrity: Maintain accurate records, ensuring data is not altered or corrupted during storage.

Retention: Store data for an appropriate duration in line with legal, regulatory, or contractual requirements, then securely dispose of it.

Security: Implement robust measures like encryption, password protection, and secure physical storage for hard copies.

Access Control: Monitor and control who can access stored data to prevent unauthorized use or breaches.

Disaster Recovery: Have plans in place for data backup and recovery to safeguard against loss from system failures or cyber-attacks.s

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Key differences between RICS guidelines and UK GDPR

A

Rics focuses on maintaining professional standards where as UK GDPR is a legal framework

Uk GDPR applies to all organisations processing data

RICS guidelines focus on client confidentiality and ethical handling of all data types

RICS is not legally enforceable although breaches may lead to disciplinary action

ANSWER: THE RICS GUIDELINES emphasise ethical professionalism and sector specific best practices, whilst UK GDPR imposes legal obligations focusing on personal data and individual rights. RICS members must adhere to both.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Data controller vs data processor

A

A data controller determines the purpose and means of the processing of personal data. A processor engages in personal data processing on behalf of the controller

17
Q

Who is the data controller

A

The company is the data controller and we have appointed a data handling officer who is the controller and decides on the purpose of data we collect and what we use it for. Adding people to mailing lists etc.

My director is the data controller I am a processor

18
Q

How do you ensure data is kept secure

A

Employ firewalls and VPNS to access data

Have password protected files