Data Management Flashcards
Why is data management important?
Data is fundamental to the role of surveyors and many of the services we provide require and depend on data. Therefore managing it correctly and using the correct sources of data is vital for our advise as real estate professionals.
What is negligence?
a failure to provide services with the standard of skill and care that would be expected from a reasonable body of the professional’s peers.
What is the legislation for data?
Data Protection Act 2018 – GDPR falls under this.
What is GDPR?
General Data Protection Regulations
What are the 8 individual rights under GDPR?
B – Right to be informed
A – Right of access
R – Right to rectification
E – Right to erasure
R – right to restrict processing
O – right to object
D – right to data portability
A – right to automated decision making/profiling
What are the 8 principles of the Data Protection Act 2018/UK GDPR?
A - Accuracy
D – Data minimisation
A - Accountability
P – Purpose Limitation (+ storage limitation)
T – Transparency, lawfulness & fairness
S – Security – integrity & confidentiality
S – Storage limitation
When must data security breaches be reported?
Data security breaches must be reported in 72 hours to the ICO (Information Commissioners Office)
Fines of up to 4% of global turnover or 20 million euros (£17.5m) – whichever is higher.
- What is the purpose of UK GDPR?
- What are three of the eight individual rights under UK GDPR?
- Who does UK GDPR apply to?
- Who is responsible for data management?
- What other methods of data security other than password encryption are available?
- What are the response procedures to an FOI request?
- What is FOI?
- What is personal data?
Cloud systems advantages
- Easier access
- Better collaboration
- Records more accurate
- Safer
- Cost effective
How do you ensure that the data you keep on your files is secure, especially when Savills acting on both tenant and landlord side?
Password protected files, lock computer when not there, work in different office/different teams.
Can you give me some of the examples of data sources you use to collate comparable/rental information?
CoStar, Savills internal data, other agent data, Athena (Savills internal data).
How do you verify the rental information?
Verify with the agent that undertook the deal.
Why would you look to CoStar for comparable evidence?
To identify deals that we may not have on our system, but would be sure to verify with the agent before using it as evidence.
Are there any instances where you have advised clients to use specific data sharing tools?
Box – accessible by all three parties involved. Equivalent to Dropbox. Improve client service, larger documents
What can you give the client for a data room?
Details of who has accessed it? Analytics behind this. This is how I am using the data for the advice. How long people have been in, what they have downloaded and when.
Use this process to advise my client.
What is the Freedom of Information Act 2000?
Gives individuals right of access to information held by public bodies.
Public body usually required to provide it within 20 working days in the format requested.
Exemptions – contrary to GDPR requirements
What is the Data Protection Act 2018?
The act defines UK law on the processing of data on identifiable living people.
How can the security of data be improved?
Firewalls, passwords, encryption
What is an NDA and how do they work?
Non-disclosure agreement.
Legal framework used to protect sensitive and confidential information (e.g. IP)
Breach may include lawsuits, fines, compensation of the value of lost properties.
Can you name some data security technologies?
Disk encryption – encrypting data on a secure drive
Regular backups off site
Password protection
Use of anti-virus software
Firewalls
2FA
Secure cloud
What technologies to Savills have in place for data security.
We have a firewall/anti-virus software called Mimecast. It scans incoming email traffic and identifies potential threats.
Windows security – protects against viruses, malware and other threats
What is malware?
Software specifically designed to disrupt, damage or gain unauthorised access to a computer system
What CPD have you undertaken for data management?
Compliance training – included overview on GDPR and how we need to comply with the regulations
When Can you process personal data?
You must have a valid lawful basis. There are 6 lawful bases for processing. Article 6 of UK GDPR:
1. Consent
2. Contract
3. Legal obligation
4. Vital interest
5. Public task
6. Legitimate interests
What are the regulations for GDPR?
General Data Protection Regulations 2016
EU law transcribed into UK la after Brexit. Supplemented by Data Protection Act 2018
What specific steps do you take to ensure compliance when mailshotting
I use our database on Agents Society where all enquiries are tracked and those with details on there have given their consent to be contacted if any future properties meet their requirements.
Is there any RICS guidance on Data Management?
There is a Professional Standard being drafted – Data Handling and Prevention of Cybercrime.
Who at your company has the overall responsibility for data protection compliance?
Overall responsibility for data protection compliance lies with the Group Legal Director & Company Secretary.
company UK monitoring compliance responsibility?
MD