Data Management Flashcards

(62 cards)

1
Q

What is GDPR? 

A

General Data Protection Regulation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is the significance of GDPR?

A

As a surveyor, I must ensure that any personal or client data is processed lawfully, stored securely, and only used for legitimate purposes in line with GDPR and the Data Protection Act 2018

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

When did GDPR come into effect?

A

25 May 2018  - same day as Data Protection Act 2018 which was to incorporate new EU GDPR Legislation.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Who regulates GDPR in the UK? 

A

Information Commissioners Office

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Key persons outlined in GDPR?

A

Controller - A data controller determines the purposes and means of the processing of personal data

Processor - A processor engages in personal data processing on behalf of the controller.

Data protection officer - Responsible for overseeing the data protection approach, strategy and implementation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is the purpose of GDPR?  

A

Protect citizens personal data  

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What constitutes personal data?

A

Any information related to a person or ‘Data Subject’ that can be used to identify a person e.g. names, photo, email address, bank details, etc 

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Examples of personal data under GDPR that could apply to property companies? 

A

Data relating to investors, fund managers, valuations, compliance, background checks by HR, etc 

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What Act implemented GDPR in the UK? 

A

Data Protection Act (2018) 

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is the significance of the Data Protection Act (2018)?

A

Controls how your personal information is used by organisations, businesses or the government. It is the UK’s implementation of the GDPR

Replaced Data Protection Act 1998 

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What are the 7 principles of Data Protection Act 2018? (AKA 7 principles of GDPR)

A

LAAPSID

Lawfulness, fairness, transparency 

Accuracy  

Accountability  

Purpose limitation 

Storage limitation 

Integrity and confidentiality 

Data minimisation 

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

8 individual rights under GDPR? (Common question)

A

Right to Information 

Right to Access 

Right to Rectification 

Right to Erasure 

Right to Restrict Processing 

Right to Data Portability 

Right to Object 

Right to Automated Decision-Making  

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

To what organisations does GDPR apply? 

A

GDPR applies to any and all businesses and organisations which are responsible for handling personal data in the European Union (and the UK)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

 What are penalties for GDPR breaches?

A

Power to issue fines of up to £17.5 million (20M euros) or 4% of your annual worldwide turnover, whichever is higher.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is the ‘right to access’ under GDPR? 

A

Individuals have the right to obtain confirmation that their data is being processed, and access to their personal data 

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is a breach notification, what are the timescales?

A

Need to report within 72 hours of becoming aware of breach  

If breach high risk, then need to notify the individual without delay 

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is ‘right to be forgotten’ under GDPR? 

A

Under Article 17 of GDPR, individuals have right to have personal data erased in certain circumstances 

Data no longer necessary for original purpose

Data been processed unlawfully  

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

How are data breaches typically discovered? 

A

Access logs, reported thefts, lost equipment or data security incident  

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

How have consent conditions been strengthened under GDPR? 

A

Consent must be given using plain and clear language 

Must be as easy to withdraw consent as it is to give it  

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

What is data portability? 

A

Right for data subject to receive personal data concerning them which they have previously provided, and have it transmitted to another controller

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

What is privacy by design? 

A

Legal requirement under GDPR  

Calls for inclusion of data protection from onset of designing systems, rather than as addition 

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

What is data protection officer? 

A

A Data Protection Officer (DPO) is a senior individual appointed to oversee a company’s data protection strategy and compliance with the UK GDPR and Data Protection Act 2018

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

Examples of data held by surveying practices?  

A

Data held to help service a Client (accounting info, compliance systems)

Emails and other correspondence

Other physical records held on file

Customer data held for marketing purposes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

What are obligations imposed by GDPR? 

A

Must have knowledge of the data you store and process (including its location and security)

Have to be able to delete every instance of an individuals data

Must demonstrate compliance in managing data

Must be able to prove how information is being used

Must offer data portability

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
RICS best practice points for complying with GDPR? 
Conduct data review   Anonymise data where possible   Encrypt everything where possible   Treat commercial data in same way as personal data, even though not covered by GDPR  Understand the data process
23
What are your company's policies for data protection breaches? 
Report to line manager or Data Protection Officer within the firm 
24
RICS recommendations for using confidential information? 
Document purposes for which you are allowed to hold information  Keep record of consent for processing, storage and retention   Check if you have appropriate contractual clauses for use of information 
25
What information should be included in firms privacy notice? 
What information you have  What information will be used for  Which third parties information will be shared with  How long information will be stored for   What legal rights they have   
26
What is SAR? 
Subject Access Request   Demand that the individual be given all the information that a company holds on them 
26
What was the Freedom of Information Act? 
Came into effect in 2000  Allows an individual to request access to information held by a public body  Public body is required to provide that information (within 20 working days) in requested format  They can charge a fee for this  
27
What is required for a Land Registry Compliant Plan?
What is required for a Land Registry Compliant Plan? Drawn to scale of 1:100 or 1:200 Have a scale measurement bar Have the scale noted on a plan Include a 1:1250 scale map of the location Full address North point Demise in red outline
28
What is the difference between a deed and a registered title?
Deed is a physical document declaring a person's legal ownership Registered title is ownership recorded with Land Registry electronically
29
Are electronic signatures accepted by the Land Registry?
Yes, witnessed electronic signatures accepted from July 2020
29
Disadvantages of the systems you use? 
Rely on data input completed by others - human error  External systems - firm is not in control of security   Not user friendly and lots of staff training required! 
30
How did it tighten up the former DPA 1998? 
Customer has greater control over their data   Harsh penalties if fail to comply - up to £17.5M GDPR is binding piece of legally enforceable regulation   Applies to all EU nations (inc. UK) and every company holding data on EU citizens   Breaches have to be reported to the relevant authorities within 72 hours   Companies will be accountable for data protection  Any firm with over 250 people requires a dedicated data protection officer  
31
Give me an example of how you process and handle confidential information. 
I use document systems to add, amend and remove information - Data input forms When sending information to solicitors, i ensure files are uploaded to a secure data room Anonymised employee liability information for TUPE Password and account to enter management systems
31
How do you comply with GDPR in your role? 
I report suspected breaches I do not give out confidential or personal information I keep records of consent for processing, storing and retaining data I understand the information we hold that is protected by GDPR
32
What does encryption mean?
Mathematical function that encodes data in such a way that only authorised users can access it
32
What is a fire wall?
Network security system that monitors and controls incoming and outgoing network traffic based on predetermined security rules
32
Tell me about how you extract data from a source regularly used in your role?
Extract data from leases and enter into a new lease input form. This is securely sent to Data Input who then upload the information to TRAMPS/Horizon where the data is held securely for those with password access
33
Can you tell me about the retention of files and the Limitations Act 1980?
Section 5 of Limitations Act 1980 says legal action must be brought within 6 years of issue arising Business then have a responsibility to keep documents for at least 6 years after they expire
34
Give me an example of how you ensure that data is kept securely. 
Access is restricted to users by password Firewalls in place by IT team to protect against hacking Appropriate training undertaken to understand processes
35
What is copyright? 
The exclusive and assignable legal right given to the originator for a fixed number of years, to print, perform, film or record literacy, artistic or musical material. 
36
Can copyright be transferred?
Yes
37
What is an AVM?
Automated Valuation Model - Mathematical / Statistical modelling with databases of existing properties and transactions to calculate real estate values
38
Does RICS provide any guidance on AVM?
INSIGHT PAPER - RICS Road Map: Automated Valuation Models Roadmap for RICS members and stakeholders, 2021
39
Explain the growing use of AVMs in the industry?
Use of computer modelling in the science of valuation has merit in a world with increased availability and use of data - may reduce expensive litigation
40
What is an Electronic Document Management System?
Type of software that stores, organises and manages documents in the form of electronic files -> Sharepoint
41
How do you ensure GDPR compliance and security in office?
Clear desk policy, lock screens, external back-up drive, password protection 
42
How do you apply your firms data protection policy?
I report suspected breaches I anonymise data where possible I don't send protected data unless it is to the individual it concerns I use password protections
42
How do you monitor compliance on QUOODA/riskwise?
Linked to my email so get notified if action required or if document is non-compliant Get notified if document becoming overdue in next 30 days/ of any actions
43
How to ensure data accuracy? 
Check against original document  Have it double checked by colleague
44
What are CPSEs?
Commercial Property Standard Enquiries 
45
If a tenant would like to access CCTV footage, what is required?
Subject Access Request - can only be given to police/insurers Liaise with Data Protection Officer on what is required / what can be given 
46
How do you store confidential data in your office? 
Login to password protected system that uses dual-factor authentication (face ID and code)  Keep data anonymised if it is personal data  
47
What would you do if you realised that you had received confidential data in an email, from another surveyor, which you should not have seen? 
Cannot use information for own purposes  Client and sender/receiver should be advised of error  Matter should be recorded in note to firms Compliance Officer  Dispose securely of the information  
48
How do you ensure the data on the systems you use is accurate?  
Internal and external systems get audited   Prelists get raised 
49
Benefits of cloud based storage systems?
Info backed up securely on encrypted servers Environmentally friendly Multiple users can assess the same docs Often cheaper
49
What is a Non-disclosure agreement - NDA for?
Used to protect against the disclosure and sharing of any confidential data
50
If two separate department within your firm were working for two rival companies how would you ensure client sensitive data was managed?
Make clients aware of risks Conflict of interest check Seek letter of instruction that both parties are happy for us to continue Implement an information barrier
51
What things must companies put in place to ensure GDPR compliance?
Raise awareness across your business - via training Audit all personal data Update privacy policy Review how we seek, obtain and record consent.
52