Data Management Flashcards

1
Q

If two separate departments at T&T were working for two competitors, how would you ensure client sensitive data was managed?

A
  • Set up password and personel restricted files
  • Segregate teams working on the same commission
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What data systems do you use at T&T?

A

The Hive
Microsoft Teams
Intranet system
Servers
Dynamics 365 for finances

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is GDPR?

A

General Data Protection Regulations - European law regarding data protection and how personal data can be used.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are the 7 principles of GDPR?

A
  1. Data Accuracy
  2. Data Minimisation
  3. Purpose limitation
  4. Storage limitation
  5. Accountability (of data)
  6. Integrity and Confidentiality
  7. Lawfulness and Transparency
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Can you name the individual rights of GDPR?

A
  1. To access
  2. To rectify
  3. To erase
  4. To object
  5. To be informed
  6. To restrict processing
  7. To data portability
  8. To automated decision making & profiling
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

How long should you keep data for?

A

6 years if underhand.
12 years if deed.
RICS recommends 15 years as this is how long claims can be up to.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is the Data Protection Act?

A

UK’s implementation of GDPR.

The act ensures data is used fairly, lawfully and transparently, used in a way that is relevant to it’s purpose and is not retained for any longer than necessary.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What are a persons right under the DPA?

A
  • To be informed
  • To access
  • To rectify (incorrect data)
  • To have data erased
  • To stop processing
  • To object to the use
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Who are the key people under the GDPR rules?

A
  • Controller - determines the purpose and means of processing the data
  • Processor - processes personal data on behalf of controller
  • Data Protection Officer - leadership role required by GDPR by companies who process data of EU citizens.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What are the sanctions for breach of GDPR?

A

Up to £20m appropriate to the breach or 4% of turnover

How well did you know this?
1
Not at all
2
3
4
5
Perfectly