Data Management Flashcards

1
Q

What is GDPR? 

A

General Data Protection Regulation

Relates to personal data

Aims to create a single data protection regime for anyone doing business in the EU and to empower individuals to take control of how their data is used by third parties

Gives people stronger rights to be informed about how their personal information is used

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

When did GDPR come into effect?

A

25 May 2018  - same day as Data Protection Act 2018 which was to incorporate new EU GDPR Legislation.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Who regulates GDPR in the UK? 

A

Information Commissioners Office 

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Key persons outlined in GDPR?

A

Controller - A data controller determines the purposes and means of the processing of personal data

Processor - A processor engages in personal data processing on behalf of the controller.

Data Protection officer - Responsible for overseeing the data protection approach, strategy and implementation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is the purpose of GDPR?  

A

Protect citizens personal data 

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What constitutes personal data? 

A

Any information related to a person or ‘Data Subject’ that can be used to identify a person e.g. names, photo, email address, bank details, etc 

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Examples of personal data under GDPR that could apply to property companies? 

A

Data relating to investors, fund managers, valuations, compliance, background checks by HR, etc 

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What Act implemented GDPR in the UK? 

A

Data Protection Act (2018)  - controls how your personal information is used by organisations, businesses or the government. It is the UK’s implementation of the GDPR

Replaced Data Protection Act 1998 

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What are the 7 principles of Data Protection Act 2018? (AKA 7 principles of GDPR)  LAAPSID

A

Lawfulness, fairness, transparency 

Accuracy  

Accountability  

Purpose limitation 

Storage limitation 

Integrity and confidentiality 

Data minimisation 

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

8 individual rights under GDPR? 

A

Right to Information 

Right to Access 

Right to Rectification 

Right to Erasure 

Right to Restrict Processing 

Right to Data Portability 

Right to Object 

Right to Automated Decision-Making  

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

To what organisations does GDPR apply? 

A

GDPR applies to any and all businesses and organisations which are responsible for handling personal data in the European Union (and the UK)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What are penalties for GDPR breaches? 

A

Power to issue fines of up to £17.5 million (20M euros) or 4% of your annual worldwide turnover, whichever is higher.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is the ‘right to access’ under GDPR? 

A

Individuals have the right to obtain confirmation that their data is being processed, and access to their personal data 

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is a breach notification under GDPR? 

A

Need to report within 72 hours of becoming aware of breach  

If breach high risk, then need to notify the individual without delay 

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

How are data breaches typically discovered? 

A

Access logs, reported thefts, lost equipment or data security incident  

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

How have consent conditions been strengthened under GDPR? 

A

Consent must be given using plain and clear language 

Must be as easy to withdraw consent as it is to give it  

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

What is ‘right to be forgotten’ under GDPR? 

A

Under Article 17 of GDPR, individuals have right to have personal data erased in certain circumstances 

Data no longer necessary for original purpose

Data been processed unlawfully 

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

What is data portability? 

A

Right for data subject to receive personal data concerning them which they have previously provided, and have it transmitted to another controller 

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

What is privacy by design? 

A

Legal requirement under GDPR  

Calls for inclusion of data protection from onset of designing systems, rather than as addition 

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

What is data protection officer?

A

An individual appointed to monitor internal compliance and advise on an organisations data protection obligations  

Only required if organisation is public body, authority or carrying out certain type of processing activity 

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

Examples of data held by surveying practices?  

A

Data held to help service a Client (accounting info, compliance systems)

Emails and other correspondence

Other physical records held on file

Customer data held for marketing purposes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

What are obligations imposed by GDPR? 

A

Must have knowledge of the data you store and process (including its location and security)

Have to be able to delete every instance of an individuals data

Must demonstrate compliance in managing data

Must be able to prove how information is being used

Must offer data portability

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

RICS best practice points for complying with GDPR? 

A

Conduct data review  

Anonymise data where possible  

Encrypt everything where possible  

Treat commercial data in same way as personal data, even though not covered by GDPR 

Understand the data process

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

What are your company’s policies for data protection breaches? 

A

Report to line manager or Data Protection Officer within the firm 

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
Q

RICS recommendations for using confidential information? 

A

Document purposes for which you are allowed to hold information 

Keep record of consent for processing, storage and retention  

Check if you have appropriate contractual clauses for use of information 

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
26
Q

What information should be included in firms privacy notice? 

A

What information you have 

What information will be used for 

Which third parties information will be shared with 

How long information will be stored for  

What legal rights they have 

27
Q

What is SAR? 

A

Subject Access Request  

Demand that the individual be given all the information that a company holds on them 

28
Q

What was the Freedom of Information Act? 

A

Came into effect in 2000 

Allows an individual to request access to information held by a public body 

Public body is required to provide that information (within 20 working days) in requested format 

They can charge a fee for this  

29
Q

What are the provisions of the Land Registry Act (2002)? 

A

Provides a complete and accurate reflection of the state of the title of the land at any given time  

Aim is to get all freehold land in England and Wales registered by 2030 

30
Q

What is required for a Land Registry Compliant Plan?

A

Drawn to scale of 1:100 or 1:200

Have a scale measurement bar

Have the scale noted on a plan

Include a 1:1250 scale map of the location

Full address

North point

Demise in red outline

31
Q

What is the difference between a deed and a registered title?

A

Deed is a physical document declaring a person’s legal ownership

Registered title is ownership recorded with Land Registry electronically

32
Q

Are electronic signatures accepted by the Land Registry?

A

Yes, witnessed electronic signatures accepted from July 2020

33
Q

Disadvantages of the systems you use? 

A

Rely on data input completed by others - human error 

External systems - firm is not in control of security  

Not user friendly and lots of staff training required!

34
Q

How did it tighten up the former DPA 1998? 

A

Customer has greater control over their data  

Harsh penalties if fail to comply - up to £17.5M

GDPR is binding piece of legally enforceable regulation  

Applies to all EU nations (inc. UK) and every company holding data on EU citizens  

Breaches have to be reported to the relevant authorities within 72 hours  

Companies will be accountable for data protection 

Any firm with over 250 people requires a dedicated data protection officer 

35
Q

How do you comply with GDPR in your role? 

A

I report suspected breaches

I do not give out confidential or personal information

I keep records of consent for processing, storing and retaining data

I understand the information we hold that is protected by GDPR

36
Q

Give me an example of how you process and handle confidential information. 

A

I use document systems to add, amend and remove information - Data input forms

When sending information to solicitors, i ensure files are uploaded to a secure data room

Anonymised employee liability information for TUPE

Password and account to enter management systems

37
Q

What does encryption mean?

A

Mathematical function that encodes data in such a way that only authorised users can access it

38
Q

What is a fire wall?

A

Network security system that monitors and controls incoming and outgoing network traffic based on predetermined security rules

39
Q

Tell me about how you extract data from a source regularly used in your role?

A

Extract data from leases and enter into a new lease input form. This is securely sent to Data Input who then upload the information to TRAMPS/Horizon where the data is held securely for those with password access

40
Q

Can you tell me about the retention of files and the Limitations Act 1980?

A

Section 5 of Limitations Act 1980 says legal action must be brought within 6 years of issue arising

Business then have a responsibility to keep documents for at least 6 years after they expire

41
Q

Give me an example of how you ensure that data is kept securely. 

A

Access is restricted to users by password

Firewalls in place by IT team to protect against hacking

Appropriate training undertaken to understand processes

42
Q

What is copyright? 

A

The exclusive and assignable legal right given to the originator for a fixed number of years, to print, perform, film or record literacy, artistic or musical material. 

43
Q

Can copyright be transferred?

44
Q

What is an AVM?

A

Automated Valuation Model

  • Mathematical / Statistical modelling with databases of existing properties and transactions to calculate real estate values
45
Q

Does RICS provide any guidance on AVM?

A

INSIGHT PAPER - RICS Road Map: Automated Valuation Models Roadmap for RICS members and stakeholders, 2021

46
Q

Explain the growing use of AVMs in the industry?

A

Use of computer modelling in the science of valuation has merit in a world with increased availability and use of data

  • may reduce expensive litigation
47
Q

What is an Electronic Document Management System?

A

Type of software that stores, organises and manages documents in the form of electronic files -> Sharepoint

48
Q

How do you ensure GDPR compliance and security in office?

A

Clear desk policy, lock screens, external back-up drive, password protection

49
Q

How do you monitor compliance on QUOODA/riskwise?

A

Linked to my email so get notified if action required or if document is non-compliant

Get notified if document becoming overdue in next 30 days/ of any actions

50
Q

How do you apply your firms data protection policy?

A

I report suspected breaches

I anonymise data where possible

I don’t send protected data unless it is to the individual it concerns

I use password protections

51
Q

How to ensure data accuracy? 

A

Check against original document 

Have it double checked by colleague

52
Q

What are CPSEs?

A

Commercial Property Standard Enquiries

53
Q

If a tenant would like to access CCTV footage, what is required? 

A

Subject Access Request - can only be given to police/insurers

Liaise with Data Protection Officer on what is required / what can be given

54
Q

How do you store confidential data in your office? 

A

Login to password protected system that uses dual-factor authentication (face ID and code) 

Keep data anonymised if it is personal data 

55
Q

What would you do if you realised that you had received confidential data in an email, from another surveyor, which you should not have seen? 

A

Cannot use information for own purposes 

Client and sender/receiver should be advised of error 

Matter should be recorded in note to firms Compliance Officer 

Dispose securely of the information

56
Q

How do you ensure the data on the systems you use is accurate?  

A

Internal and external systems get audited  

Prelists get raised 

57
Q

Benefits of cloud based storage systems?

A

Info backed up securely on encrypted servers

Environmentally friendly

Multiple users can assess the same docs

Often cheaper

58
Q

Non-disclosure agreement - NDA

A

Used to protect against the disclosure and sharing of any confidential data

59
Q

If two separate department within your firm were working for two rival companies how would you ensure client sensitive data was managed?

A

Make clients aware of risks

Conflict of interest check

Seek letter of instruction that both parties are happy for us to continue

Implement an information barrier

60
Q

What things must companies put in place to ensure GDPR compliance?

A

Raise awareness across your business - via training

Audit all personal data

Update privacy policy

Review how we seek, obtain and record consent.

61
Q

Data portability

A

individuals or organizations have control over their data and can easily switch

62
Q

How have you advised client on DM

A

Recognised MEES coming to force old managing agents didn’t have a tracker for EPC

63
Q

Horizon limitations

A

3rd party we don’t have control of the security

Human error

Training not user friendly