Data management Flashcards

1
Q

Can you name the recently introduced regulations set out to control how companies manage data they hold?

A

The General Data Protection Regulation 2016

-EU’s legislation that governs how personal data is handled

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Can you name legislation this is supported by?

A

The data protection act 2018

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

How does GDPR affect your working activities?

A

I apply the Data Protection Act 2018 in my daily work by ensuring that I handle personal data in accordance with the principles of the Act. This includes:

Notifying individuals about how their personal data will be used and stored

Ensuring that personal data is accurate and up-to-date

Storing personal data securely, using encryption and access controls as necessary

Only collecting and processing personal data that is necessary for the purposes of the project

Ensuring that personal data is not shared with third parties without the individual’s consent

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Can you name any of the principles covered in the Data Protection Act 2018?

A
  1. Used fairly, lawfully and transparently
  2. Used specific, explicit for the purposes as intended
  3. Used in a way that is adequate, relevant and limited only to what is necessary
  4. Kept no longer than is necessary
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

How does CBRE comply with GDPR?

A
  1. Only collect data for a specific purpose
  2. Kept in a safe location
  3. Kept accurate and up to date
  4. Has a data protection officer (DPO)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is meant by ‘to be forgotten’?

A
  1. It is one of the fundamental rights introduced by GDPR
  2. Allows an individual to request removal of their data on databases under specific circumstances
  3. When they withdraw consent
  4. When storage of their data is no longer required
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

How do would you deal with cyber security at home or hybrid working?

A
  1. Ensure laptop and phones have passwords
  2. Microsoft two factor authentication on my phone for logging into outlook or Microsoft apps
  3. Use a secure WiFi connection at home and at work
  4. Antivirus software on my laptop
  5. Remote access policies
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What are current challenges that Covid and or Brexit is bringing to data management?

A
  1. UK organisation must navigate new data transfer mechanisms to ensure compliance with EU data protection laws, while EU organisations may face additional regulatory hurdles when transferring data to and from the UK
  2. Hybrid working - need to increase cyber security and ensure data is protected
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What are 7 key principles under GDPR?

A
  1. Lawfulness, fairness and transparency.
  2. Purpose limitation.
  3. Data minimisation.
  4. Accuracy.
  5. Storage limitation.
  6. Integrity and confidentiality (security).
  7. Accountability.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What are the 8 individual rights under GDPR?

A
  1. To be informed
  2. To access
  3. To rectification
  4. To erasure
  5. To restrict processing
  6. To data portability
  7. To object
  8. To automated decision making and profiling
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

How long do you need to keep data for?

A
  1. 6 years if contract is signed under hand
  2. 12 years if contact is signed under deed
  3. RICS recommend 15 years, as this is the end of the limitation period
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What type of data systems does CBRE use?

A
  1. Cloud based transfer
  2. Microsoft one drive
  3. Back up server
  4. For Common data environments I used AutoDesk Construction Cloud
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What are the key persons identified in GDPR?

A
  1. Data Controller
  2. Data Processor
  3. Data Subject
  4. Data Protection Officer
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Who enforces GDPR?

A

The Information Commissioner’s Office (ICO)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What are are the fines of Non Compliance with GDPR?

A

£17.5 million fine or 4% of annual turn over, whichever is greatest

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is an information barrier?

A

A physical or electronic separation between individuals within the same firm to protect confidential information

17
Q

When does the Data Protection Act apply?

A

If you are collecting personal data for an organisation

18
Q

Who is the data controller?

A

The organisation processing the information

19
Q

What would you do in the event of a data breach?

A

Contract IT
Inform line manager
Notify ICO within 72 hrs

20
Q

What is the difference between GDPR 16 and DPA 18?

A

GDPR states that a child can consent to data processing at 16, DPA is 13

GDPR gives people the right to automated decision making. DPA allows automated decision making if there are valid reason for it.

21
Q

What is the 3-2-1 backup rule?

A

3 copies of data - Create 3 copies of your data ie original and 2 back ups.
2 media types - Hard drive and CBRE secure server
1 offsite copy - CBRE secure server

22
Q

Which legislation gives individuals the right to access any information held by public bodies?

A

Freedom of information Act 2000

23
Q

Are there any exemption to the FIA 2000?

A

Only information that would prejudice a criminal matter or break GDPR requirments is not allowed.

24
Q

What must companies do to comply with the Data Protect Act 2018

A

Register with the information commissioners office (ICO) and pay an annual fee

25
Q

How do you ensure confidentiality of clients data?

A

Data is handled in accordance with the Data Protect act 2018

  • I follow the guidance on CBRE best practice documents
  • Only collecting and processing personal data that is necessary for the purposes of the project
  • Ensuring that personal data is not shared with third parties without the individual’s consent
  • Pointcloud data for example is kept for retention for 6 years
26
Q

What does the Freedom of Information Act 2000 require of public bodies?

A

A public body must tell anyone who asks where it holds the requested information.

The public body usually has to provide the information within 20 working days and in the format requested.

The public body can charge a fee for providing the information.

27
Q

What are the RICS Data Standards, 2018?

A

Set of stabdards ti suppoort the capture, verifcation and sharing of data in a common format

They address issues of digital data consistency

28
Q

What data are the RICS Data Standards, 2018 already available for?

A

International Property Measurement Standards (IPMS)

29
Q

What is included in a Land Registry title register?

A

A: Property Register - description of the property, tenure, the data the property was first registered and any rights it may benefit from e.g. private right of way

B: Proprietorship register - name and address of the current owner, when they bought the property, how much was paid for it (if sold since 1 April 2000), any restrictions that limit power of the owner and the class of the title

C: Charges register - mortgages and other financial burdens received on the property. Other rights or interest that limit how the land or property can be used e.g leases, rights of way or covenants

30
Q

What is ‘personal data’ as defined by GDPR?

A

as any information relating to an identified or identifiable natural person (referred to as a “data subject”). This means any piece of information that can directly or indirectly identify a person.

31
Q

What is a SAR?

A

Subject access request

  • Gives individuals rights to request any ‘personal data’ held on them. This right is a principle of GDPR
32
Q

What is SOC2?

A

SOC 2 stands for System and Organization Controls 2. It was created by the American Institute of Certified Public Accountants (AICPA) as a way to help organizations verify their security and reduce the risk of a security breach.

33
Q

What UK Security Standards adopt when consider Data Management Strategy?

A

ISO 27001

This standard provides a framework for establishing, implementing, maintaining, and continually improving ISMS. It outlines a risk management process involving people, processes, and IT systems.

34
Q

What is Scoptio?