Data Management Flashcards

1
Q

What legislation covers the functions of the VOA?

A

Commissioners for Revenue and Customs Act (CRCA) 2005

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Which section of the CRCA covers VOA statutory duties?

A

Section 7

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Which section of CRCA covers the VOA providing valuations?

A

Section 10.

Any purpose relating to functions of HMRC.
At the request of a public authority
At the request of any person in relation to a public function or of a public nature

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Which sections of CRCA relate to disclosure?

A

Sections 17-23

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is section 17 of CRCA?

A

Allows sharing if information held for one function with another function within HMRC and VOA

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is section 18 CRCA?

A

Sets out the circumstances when HMRC and VOA may disclose information outside HMRC and VOA

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Who is VOA data controller?

A

HMRC

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is Section 19 of CRCA?

A

Criminal offence for VOA officers to disclose information if not covered by section 18.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What are sections 20-21 of CRCA?

A

Covers when information can be disclosed where it is in public interest or is to a prosecuting authority

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What are sections 22-23 of CRCA?

A

Related to the rights to information under GDPR and FOIA and set out how these requests should be treated

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is personal data?

A

Anything that can lead to the identification of a person

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What are the 4 categories of data in the VOA?

A

People Personal (personal data)
Property personal (property data)
Sensitive personal (data that could damage VOA reputation)
Special category (race, ethnicity, biometrics etc)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Which act covers UK data protection?

A

Data Protection Act 2018

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Who regulates data protection in the UK?

A

Information Commussioners Office (ICO)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Who has the responsibility for storage and usage of data?

A

The individual

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

7 principles of GDPR?

A
  1. Lawfullness, fairness and
    transparency
  2. Purpose limitation
  3. Data minimisation
  4. Accuracy
  5. Storage limitation
  6. Integrity and confidentiality
  7. Accountability
17
Q

What are the retention schedules for data in the VOA?

A

Revaluation data: longer of (a) life of the list in force plus 5 years or (b) 1 year
Personal images; until consen5 is withdrawn
Council tax: life of the list plus 6 years
Customer correspondence: 6 months from date of delivery

18
Q

What are the individual lights under Data Protection legislation

A

Living individuals have rights:
1. Be informed
2. Access data
3. Erasure
4. Restrict
5. Data portability
6. Object to processing
7. Withdraw consent
8. Complaints to ICO
9. Rights in relation to automated decision making and profiling

19
Q

How many days to respond to requests for individual rights under Data Protection legislation?

20
Q

Which act covers copyright?

A

Copyright, designs, and patents act 1988 (CDPA)

21
Q

When is the copying of material permitted?

A

Nesecarry for the performance of a statutory function (Section 50 CDPA)
In the course of judicial proceedings (Sectoon 45 CDPA)
Received express permission of the copyright owner
Done in accordance with rerms and conditions of the publisher/website or licence held

22
Q

What is crown copyright?

A

Anything created by civil servants during life of service related to their functions is owned by the crown

23
Q

Which act manages records and information in the VOA?

A

Public Records Act (PRA)

24
Q

What are the VOA responsibilities under the PRA?

A

Review records regularly and preserve after 20 years at national archives.
Obtain permission to retain records over 20 years, which don’t meet the criteria for preservation.
Destroy records in line with local agreed retention schedules

25
Q

What should you be mindful of during Management of Records?

A

Code of practice within section 46 of the FOIA

26
Q

How long should you retain agency information?

A

Review the VOA data and information retention schedule, and if unsure, speak to information asset owner.

28
Q

Where can VOA information be stored?

A

VoS, EDRM, Sharepoint, Shared Drives, ERP, Hardcopy and more. But each has its own governance and restrictions to what can be stored.

29
Q

Where can customer data not be stored?

A

OneDrive and Teams
Outlook for a maximum of 6 months

30
Q

What is LADPASS?

A

Principles of Data Protection Legislation
L - Lawfullness, Transparency and Fairness
A - Accuracy
D - Data Minimisation
P - Purpose Limitation
A - Accountability
S - Storage Limitation
S - Security

31
Q

What is AORAIDER?

A

Rights under Data Protection

A - Access
O - Object
R - Rectified
A - Automated Data
I - Informed consent
D - Data portability
E - Erasure
R - Restrict

32
Q

When should Data breached be reported?

A

As soon as possible, but within 48 hours of when it was first identified

33
Q

What is a data breach?

A

Breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access to personal data.

34
Q

When should data breached be reported to ICO?

A

Within 72 hours if there is significant high risk to an individual

36
Q

Examples of data breaches?

A

Email sent to wrong person or not BCC
Hardcopy post two letters in one envelope
Data not kept up to date
Wrong fields completed on CDB
Not accurately redacting personal data
Publishing copy material on the intranet
Data loss
Housekeeping: holding records longer than agreed retention periods

37
Q

How do you ensure compliance with data protection legislation?

A
  1. Know your guidance and processes
  2. Take time to read news and updates
  3. Complete data protection impact assessments
  4. Complete mandatory e-learning
  5. Report security incidents breaches or concers
38
Q

Who is the data protection officer for the VOA?

A

David Burke