Data Management Flashcards
If two separate departments within your firm were working for two competitors, how would you ensure client sensitive data was managed?
- Set up password and personel restricted files
- Segregate teams working on the same commission
- Information barriers / physical barriers
What data systems do you use at CBRE?
Microsoft Teams
SharePoint
Client IQ / CIQ
Shared Drive (S:Drive)
What is GDPR?
General Data Protection Regulations - law regarding data protection and how personal data can be used.
Can you name the individual rights of GDPR?
8 rights
- Right to be informed
- Right of access
- Right to rectification
- Right to erasure
- Right to restrict processing
- Right to data portability (to use for their own purposes)
- Right to object
- Rights to automated decision making and profiling (as undertaken by insurance companies)
How long should you keep data for?
6 years if underhand.
12 years if deed.
RICS recommends 15 years as this is how long claims can be up to.
What is the Data Protection Act?
UK’s implementation of GDPR.
The act ensures data is used fairly, lawfully and transparently, used in a way that is relevant to it’s purpose and is not retained for any longer than necessary.
What are a persons right under the DPA?
- To be informed
- To access
- To rectify (incorrect data)
- To have data erased
- To stop processing
- To object to the use
Who are the key people under the GDPR rules?
- Controller - determines the purpose and means of processing the data
- Processor - processes personal data on behalf of controller
- Data Protection Officer - leadership role required by GDPR by companies who process data of EU citizens.
What are the sanctions for breach of GDPR?
Up to £20m appropriate to the breach or 4% of turnover
What is data triangulation?
When considering reliability of data and risks, where possible, verify data against alternative source through ‘triangulation’.
Who enforces GDPR? Say there is a breach of data, who enforces GDPR?
ICO – Information Commissioners Office
What enforcing powers does the Informations Commissions Offuce (ICO) have?
- Conduct audit checks to check you are complying with obligations
- Serve an Enforcement Notice order if there has been a breach
- Issue Monetary penalties – fines
- Prosecute you if you fail to comply with Enforcement Notices
- Report to Parliament on issues of concern.
ICO also has the power to impose more substantial fines of up to £17.5 million, or 4% of your total worldwide annual turnover, whichever is higher.
What actions are undertaken at CBRE to ensure data security?
- Mandatory training
- CBRE File transfer systems
- Firewalls and blocked sites
- Phishing security check on emails – IT team verify if email/link is safe.
- Password protected computers – password updated every 3 months
- Email retention
Name some data security technologies.
- regular backups off site,
- password protection,
- anti-virus software,
- firewalls,
What is copyright?
- It is rights granted to author for the right to copy.
- Crown Copyright refers to Government material such as laws, official press, press releases, OS mapping.
- You must acknowledge copyright in your work.
Does EU GDPR apply to the UK?
- No, EU GDPR no longer applies in UK and entirely replaced by UK GDPR.
- UK GDPR is supplemented by Data Protection Act 2018 (this replaces Data Protection Act 1998).
- It gives people right to be informed about how their personal information is used.
What is a data controller?
Article 5(2) of UK GDPR requires that “the controller shall be responsible for, and be able to demonstrate, compliance with the principles”
What is Data Accountability?
- Ensures organisations prove to the Information Commissioners Office (ICO) that they comply with new regulations
In what timeframe do data breaches need to be reported to ICO?
- 72hrs where there is loss of personal data and risk of harm to individuals.
What is the fine for a data breach?
- 4% global turnover of the company or £17.5m (whichever is greater)
What is the Freedom of Information Act 2000
Gives individuals the right to access information held by public bodies.
* Public body must tell individual requesting the data whether it holds it
* Public body must supply data in 20 working days in the format requested.
* It can charge for the provision of the information.
Exemptions are allowed if contrary to GDPR requirements.
What is NDAs?
Non-Disclosure Agreement.
Prevents all involved parties from sharing any data about the relevant project or process.
Who is Data Protection Officer at CBRE?
- Geraldine Mash until she retired. Now Sarah Butterworth
Is breaching GDPR civil or criminal offence?
Criminal
What are the 7 principles of the Data Protection Act?
- Lawfulness, fairness, and transparency;
- Purpose limitation;
- Data minimisation;
- Accuracy;
- Storage limitation;
- Integrity and confidentiality;
- Accountability