Data Management Flashcards

1
Q

What are the GDPR consumer rights?

A

A - Access
C – Consent
C - Correction
E – Erasure
P – Data Portability
ACCEP
(Accep your rights)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What regulation governs laws on data protection and privacy?

A

UK General Data Protection Regulation 202

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Article 5 of GDPR requires that personal data should be what? Name at least 3.

A

Processed lawfully, fairly in a transparent manner (PLT)

Adequate, relevant, and limited to what is necessary

Collected for specified explicit and legitimate purposes

Kept in a form that permits identification of data for no longer than is necessary

Accurate and kept up to date, where necessary

Processed in a manner that ensures appropriate security of personal data.

PACKAP

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is the maximum GDPR fine set by UK GDPR and DPA 2018?

A

17.5 Million or 4% of annual global turnover (whichever is highest).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Data offences can be punished by what? Name two (excluding fines).

A

Warnings

Temporary or permanent ban on data processing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is DPA 2018?

A

Data Protection Act 2018

UK’s implementation of GDPR

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Are you aware of the Freedom of Information Act 2000?

A

Yes, it provides the public access to information held by public authorities.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

How do FOI Act 2000 requests work?

A

Must be in writing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What security measures can you use to protect data?

A

Password protection
Security markings
Physically locking storage units
Encryption firewalls
Two factor authentication

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What best practices would you encourage in terms of managing data?

A

Cross reference computer with hard copy

Back up IT systems

Write once, read many times

Keep an audit trail

Ensure electronic signature cannot be altered. (send PDFs not word)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Tell me what you know about GDPR.

A

General Data Protection Regulation

Article 5 sets out the consumer rights which includes the right to be informed, right to access, right to erase, right to correct and right to withdraw consent.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is the definition of personal data?

A

Personal data are any information which are related to an identified or identifiable person.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is encryption/firewalls/blockchain?

A

Encryption is a means of securing data by encoding it mathematically such that it can only be read, or decrypted, by those with the correct key or cipher.

A firewall is a network security device that monitors traffic to or from your network. It allows or blocks traffic based on a defined set of security rules.

A blockchain is a digitally distributed, decentralized, public ledger that exists across a network.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Tell me about how you extract data from a source regularly used in your role.

A

Internal database – CDB for rental information

Set parameters for data to refine prior to download

Use filters on excel to refine the data to what I need

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is an electronic document management system (EDMS)?

A

Software package designed to manage electronic information and records within an organisation’s workflow.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Give me an example of how you ensure that data is kept securely.

A

Permission levels, back up systems, sensitive tag

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

How do you validate information?

A

Cross check with another source

Call to get further information / confirm details

Adopt a common sense approach

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

What are pros/cons of primary data sources?

A

Pros
Greater control (type of data, design, method)
May be more accurate

Cons
Expensive (may make it more difficult)
Time consuming

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

What are pros/cons of secondary data sources?

A

Pros
Easily accessible
Affordable

Cons
May lack reliability
May be outdated

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

You shared rental evidence with an agent for rating purposes, did you have permission to share that information?

A

Yes - The Valuation Office Agency (VOA), as an executive agency of HMRC, is subject to the Commissioners for Revenue and Customs Act 2005 (CRCA)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

Can other colleagues access information you are working on?

A

No, if they are in a different team e.g. DVS then they will not be able to access information stored for rating purposes.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

Freedom of Information Act 2000 exemptions?

A

Personal data
National security

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

Tell me more about the Data Protection Act 2018.

A

The Data Protection Act 2018 controls how your personal information is used by organisations, businesses or the government.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

What regulation covers sharing data?

A

Commissioners for Revenue and Customs Act 2005

CRCA ACT

25
Q

Benefits of cloud-based systems?

A

Information is backed up by encrypted servers

Accessibility can be managed via online settings

Cheaper than physically storing and managing files

More convenient to send and share files online instead of mailing physical copies

26
Q

Meaning of a non-disclosure agreement?

A

Used to protect against the disclosure or sharing of any confidential data.

27
Q

Who are the key persons outlined within GDPR?

A

Controller – person that determines the purpose and means of processing personal data e.g. the employer.

Processor – person that processes personal data on behalf of the controller e.g., call centres acting on behalf of its client.

Data Protection Officer – leadership role required by EU GDPR. Responsible for overseeing the data protection approach strategy and implementation.

28
Q

What should companies put into place to ensure GDPR compliance?

A

Raise awareness across the business

Audit personal data

Review procedures supporting individual rights

Identify and document the legal basis for processing personal data under GDPR

Train staff and give them the information

29
Q

What personal and confidential information does the VO hold?

A

Personal data relating to VOA employees

Emails containing sensitive or confidential information

Customer correspondence received in confidence

Customer records

Property information

Contractual information

30
Q

Define what disclosure means?

A

The sharing of information with others

31
Q

What does CRCA set the VO’s functions as?

A

Producing rating lists

Council tax valuation lists

Valuation of property

32
Q

What two ways does the Freedom of Information Act provide the public with access to information held by public authorities?

A

Public authorities are obliged to publish certain information about their activities.

Members of the public are entitled to request information from public authorities.

33
Q

When would you disclose information about taxpayers (or their properties) or our customers to third parties?

A

In line with CRCA Act 2005:

If essential for one of our functions

In line with legislation or statutory gateway under LGFA

With consent of the taxpayer, customer or client

For civil proceedings such as valuation tribunal hearings

34
Q

How would you deal with someone requesting to access their own personal information?

A

There is a deadline of one month to respond to a request. I would forward any request where a requester asks for their own information to the SAR inbox immediately by emailing.

35
Q

How would you deal with a Freedom of Information request?

A

Check the request is made in writing (email/letter)

Check it includes the requester’s name and address and clearly describe the information wanted.

Forward request to FOI inbox team

36
Q

How do you store data?

A

When gathering data for any reason I always ensure to place it within the VOA’s secure drives. Case documents go in restricted drives where only certain staff can reach.

37
Q

Why did you use external sources for the house in Newport?

A

This was to verify the information held on the VOA database to ensure correct information was being used.

38
Q

How did you restrict the files for the house in Newport?

A

I ensured the files set up had permissions set for only the people working on the project.

39
Q

What advice did you provide for the land in Worcestershire?

A

This was an analysis of a land sale in the county. Following this I saved the data in secured files in a database showing its price per acre and what the use was for.

40
Q

Where was the data stored?

A

Two secured VOA drives. One so that the valuer can download the sale alongside others when needed and another database I created to describe what the land was for.

41
Q

What advice did you provide for the land in Herefordshire?

A

I advised my supervisor of the database I created for them to use in a development appraisal this included house sales, land sales.

42
Q

What are the seven principles of GDPR?

A

Lawfulness, fairness and transparency
Purpose limitation
Data minimisation
Accuracy
Storage limitation
Integrity and confidentiality
Accountability

43
Q

What is a data controller?

A

Determines the purposes and means of processing personal data.

44
Q

What is a data processor?

A

Processes personal data only on behalf of the controller.

45
Q

What is discrete data?

A

Discrete data is information that can only take certain values. Such as the profit of a company.

46
Q

What is continuous data?

A

Continuous data is data that can take any value. Such as Height, weight, temperature.

47
Q

How long to report a data breach?

A

48 hours to report internally

72 hours to report to Information Commissioners Office - legally.

48
Q

What is CRCA?

A

The Commissioners of Revenue and Customs Act (CRCA) 2005 is the Act of Parliament that created HM Revenue and Customs (HMRC) in April 2005. The Act also puts those functions formerly undertaken by the Valuation Office Agency in respect of the valuation of property on a statutory footing specifically referring to the Valuation Office Agency (VOA) in section 10.

49
Q

Where are the functions of the VOA stored?

A

Schedule 1 Section 7 and Section 10 of CRCA

50
Q

What does section 7 refer to?

A
  • Rating Lists and Council Tax Valuation Lists, and the valuation of property.
51
Q

What does section 10 refer to?

A

allows VOA to provide a valuation of property;

§ For any purpose relating to the functions of HMRC, [being for Rating Lists and Council Tax Valuation lists, or HMRC functions such as Inheritance Tax];

§ At the request of a public authority [allowing for Property Services to undertake work for other public bodies];

§ At the request of any other person, if the valuation is necessary or expedient, in connection with:

· (i) the exercise of a function of a public nature; or

· (ii) the management of money or assets received from a person, exercising functions of a public nature;

§ To advise about matters connected to the valuation of property [this is the test against which VOA determines the work it can do].

52
Q

What does section 17 refer to?

A

allows sharing of information held for one function with another function (within HMRC and VOA)

53
Q

What does section 18 refer to?

A

sets out the circumstances when HMRC and VOA may disclose information outside HMRC and VOA [Note – it doesn’t say we must supply]

54
Q

What does section 19 refer to?

A

it is a criminal offence for VOA officers to disclose VOA information that either identifies a legal person or enables their identity to be deduced when it is not covered by the circumstances set out in section 18

55
Q

What do sections 20 and 21 refer to?

A

covers when information can be disclosed where it is either in the public interest or is to a prosecuting authority.

56
Q

What do sections 22 and 23 refer to?

A

relates to the rights to information under GDPR and FOIA and set out how these requests should be treated

57
Q

Which regulation within the Non-Domestic Rating (Alterations of Lists and Appeals) England allows the VO to share information such as FOR details which relate to the grounds of the proposal?

A

Regulation 9 (7)

Or
Section 18 of the Commissioner for Revenue and Customs Act would also allow the VO to disclose FOR information if it is for the purpose of one of our functions.

58
Q

Which regulation within the Valuation Tribunal for England (Council Tax and Rating Appeals) (Procedure) Regulations 2009