Data Management Flashcards

1
Q

What is GDPR

A

The EU General Data Protection Regulations is a legal framework replacing data protection directive which sets guidelines for the collection and procession of personal information. It came into force in May 2018 and was designed to harmonise data privacy laws across Europe, to protect and empower all EU citizens data privacy and reshape the way organisations approach data privacy.
There are new rights for people to access information companies hold about them, obligations for better data management and a new regime for breaches and fines.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is personal data?

A

Any information related to a person that can be used to directly or indirectly identify a person, such as name, photo, bank details, email address etc.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is a data subject?

A

The person who’s personal data it is

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is the data protection authority?

A

The DPA is the national authority responsible for implementing and enforcing GDPR.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is the data protection officer?

A

The individual person within an organisation responsible for data protection compliance.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is the data controller?

A

The person who decides the purpose for which any personal data is to be processed and the way in which it is to be processed.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is the data processor?

A

Third parties that process data on behalf of the data controller.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is the difference between the data controller and the data processor?

A

A controller is the entity that determines the purpose, conditions and means of the processing of personal data, while the processor is an entity which processes personal data on behalf of the controller.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

When should a business appoint a DPO?

A

If (a) a public authority
(B) an organisation that engages in large scale systematic monitoring or (c) organisations that engage in large scale processing of sensitive personal data.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What are the fines for GDPR

A

The maximum fine is up to €20m or 4% of a firms annual global turnover (which ever is greater)

For smaller offences like not having records in order, could result in fines of €10m or 2% of a firms global turnover (which ever is greater) in

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

How will GDPR affect surveying practices

A

It will impact:

  • the data you hold for your clients
  • any working papers that support your compliance work which contain personal data
  • any customer data held for marketing purposes
  • emails and correspondence
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is best practice with GDPR?

A

Conduct a date review/ audit
Anonymise data wherever possible me
Encrypt everything
Create a breach response policy - a plan should be in place to handle clients request for data
Have a robust data handling policy for al data
Data storage - there are no minimum and maximum periods so the firm needs to decide what’s necessary but must ask itself why it believes it is necessary to continue to hold personal information

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is a GDPR breach?

A

A breach of security leading to an accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access to personal data transmitted, stored or otherwise processed. A breach must be reported to the national regulator within 72 hours or becoming aware of it.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Who regulates the GDPR?

A

In the U.K. it is the Information Commissioners Office (ICO).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What’s the difference between regulations and directive?

A

Regulation is a binding legislative act. It must be applied in its entirety across the EU, while a directive is a legislative act that sets out a goal that all EU countries must achieve. GDPR is a regulation as opposed to previous legislation which was a directive.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What are some of the key changes of GDPR?

A

The key changes of GDPR are:

  1. It applies to all companies processing data of data subjects in the EU
  2. Private individuals not engaged in business activities are now exempt. You are free at home to store personal contact details for personal use only.
  3. Penalties - organisations in breach can be fined up to 4% of their annual turnover or €20m, whichever is greater.
  4. Consent must be clear and distinguishable and in clear plain language. It must be easy to withdraw consent.
  5. Breach notification are 72hours from when you become aware of the breach.
  6. Rights to access - individuals have the right to obtain confirmation that their data is being processed and have access to their personal data’s
  7. Right to be forgotten - individuals have the right for their personal data to be forgotten and erased.
17
Q

Why do you think confidentiality is important?

A

I think that it shows you are trustworthy and respectful which I believe shows integrity and ethical behaviour.

18
Q

How do you store information and discard of it?

A

CBRE uses a standard filing system and we need to adhere to ISO9001. We are audited internally and externally on a regular basis and therefore have to ensure we file documents correctly. With confidential information I would make sure I discard in confidential waste bins. I would also make sure that any documentation being kept as hard copies is archived appropriately.

19
Q

What is BIM?

A

Building information modelling is a process for creating and managing information on a construction project across its lifecycle. It gives a digital description of every aspect of the built asset. It enables those who interact with the building to optimise actions. There are different levels to BIM, 0 being simplist form with no collaboration only 2D drawings, 1 being a mixture of 3D concept work and 2D, 2 being collaborative working and requires an information exchange process.

20
Q

What are the benefits of BIM?

A
  1. Better collaboration
  2. Improved coordination
  3. Reduced costs and mitigated risk
  4. Improved scheduling and sequencing
  5. Increased productivity
  6. Safer construction sites
21
Q

How can BIM Gelo the construction stage?

A

During the construction stage, the BIM model can be used as a coordination tool. The model can be used to deliver updates to the team and can be updated to include changes. Working with the FM team, the handover strategy will he developed to ensure the seamless transition from construction to operation. At the end of construction, the ‘as constructed’ BIM model will be prepared to incorporate project changes and where appropriate, warranty information compiled.

22
Q

How does BIM help during the operations stage?

A

During the operations stage of a project BIM can assist with scheduling maintenance tasks and managing the building. You can use the model for generating annual maintenance plans or easily locate parts that require maintenance.

23
Q

What are the different levels of BIM?

A

Level 0 - describes unmanaged CAD (computer aided design)

Level 1 - describes managed CAD in 2D or 3D

Level 2 - involves developing building information in a collaborative 3D environment with data attached but created in separate discipline models

24
Q

What is ISO9001

A

ISO 9001 is a quality management system based on a number of quality management principles which help to ensure greater consistency and good quality produces and services.

25
Q

What is an NDA?

A

non-disclosure agreement. confidentiality agreement and if a breach occurs you can claim damages.

26
Q

What is ISO14001?

A

It is an environmental management system where you record your energy usage, waste management and how you manage compliance obligations. Again will be subject to audit.