Data Management Flashcards

1
Q

What are the key principles of GDPR?

A

*Relates to personal data
*Should only be held with the opt in of the individual
*They have the right to access it, rectify it, erase it, right to be informed, right to object, right to data portability
*Applies the companies in the eu and those outside that offer services in the EU
*Must keep personal data accurate and up to date
*Can only be kept for the purposes it was collected for
*Should be erased as soon as it is not needed for those purposes
*Need a data controller who is responsible
*Must be kept secure

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are the penalties for noncompliance?

A

4% of global turnover or £17.5m whichever is higher

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

How do you handle personal data in compliance with GDPR?

A

Keep data securely, get consent, erase it after it is no longer needed.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Who does GDPR apply to?

A

Applies the companies in the eu and those outside that offer services in the EU

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

How does GDPR affect what you do in your role at Bruntwood?

A

The main personal data I hold is contact details for clients and other consultants. I ensure this is stored securely in a password protected information system and I have their consent to email.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

How do you know you have their consent to email them?

A

GDPR means you must have a valid legal basis for holding/ processing personal data. There are 6 legal basis – consent, carrying out of a contract, legitimate interest, vital interest, legal requirement, public interest.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What specific types of data do you typically collect and store using systems like Google Drive, Viewpoint, and Salesforce?

A

We store various types of data, such as project information, project directories, contract documentation, and lease agreements. Salesforce is primarily used for managing internal project settings and customer information, while Google Drive and Viewpoint help store and share project-specific files.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

How do you ensure that data stored in these systems is organised and easily retrievable?

A

We use standardised naming conventions and folder structures to ensure files are organised across the business.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Could you provide examples of how you use the solicitors’ online portal to manage build contracts and leases?

A

The portal allows us to upload, review, and securely store finalised contracts and lease documents.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What additional measures, besides passwords and firewalls, do you implement to ensure the security of these data management systems?

A

We enforce multi-factor authentication (MFA) for system access, conduct regular security audits, and limit user permissions based on roles.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Could you explain why GDPR compliance is critical in your business?

A

GDPR compliance is critical because it protects individuals’ rights, helps us avoid fines, and maintains trust with clients and stakeholders by demonstrating our commitment to data privacy and security

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is the Data Protection Act 2018?

A

*Provides guidance and best practice rules for organisations to follow on how to use personal data.
*UK GDPR is covered by the Data Protection Act 2010

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What are the 8 individual rights under UK GDPR?

A

Right to be informed
Right of access
Right to rectification
Right to erase
Right to restrict processing
Right to data portability
Right to object
Right to automated decision making and profiling

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is a fire wall?

A

Creates a safety barrier between a private network and public internet

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Does your firm provide you with any data protection training?

A

Regular training materials on our training platform Kallidus, informs of any policy updates

How well did you know this?
1
Not at all
2
3
4
5
Perfectly