Data Management - Level 1 Flashcards
What does the Data Protection Act (2018) set out?
Data Protection Act (2018)
Controls how personal information can be used and your rights to ask for information about yourself
Sets out the need to use information;
- Fairly
- Lawfully
- Transparently
What are the key principles of the General Data Protection Regulation?
- Lawfulness, fairness, transparency
- Purpose limitation
- Data minimisation
- Accuracy
- Storage limitation
- Integrity and confidentiality
- Accountability
How do you comply with GDPR and the Data Protection Act 2018 in your role?
To ensure compliance with GDPR and the Data Protection Act I take the following steps in my day to day work:
- Ensure access to data is only granted to people who require it
I ensure that all files and folders are labelled correctly - Secure confidential and sensitive information with password encryption
- Only share data using secure systems
- Right to collect is something we actively do in the Check Stage of CCA and in Form of Return where personal data is explicitly collected
- FOR data not disclosed outside agency
What does the Freedom of Information Act (2000) set out?
Provides public access to information held by public authorities
It does this in two ways:
- Public authorities are obliged to publish certain information about their activities
- Members of the public are entitled to request information from public authorities
Give me an example of how you ensure that data is kept securely
- Disk Encryption
- Back up data
- Password protection
- Anti-virus software
- Firewalls and Disaster Recovery Programs
What is copyright?
Copyright - Copyright is a type of intellectual property that protects original works and stops other people using it without your permission
Can copyright be transferred?
A copyright owner can sell or transfer their rights to someone else. This is known as a copyright assignment.
How do you validate information?
Source – is the source credible and reliable
Time – how recent is the information gathered is it as up to date as possible
Relevance – is the information gather directly related to your need or purpose
Sense check – try to verify the information by cross referencing
Can you tell me about the retention of files and the Limitation Act 1980?
Limitation Act (1980)
- Purpose is to set the time limits on various types of legal action, from this businesses can determine how long they need to keep documents states that legal action must be brought within six years of the issue arising.
- Businesses, then, have a responsibility to keep these documents for at least six years after they expire so they can refer to them if there’s a disagreement
What is the Land Registry used for?
Land Registry – used to access a title register which includes:
- Title number
- Ownership
- How much the property was last sold for
- Whether the property has a mortgage
- Details of ‘restrictive covenants’ - promises to not do certain things with the land, like not building on a particular area
- Details of any ‘easements’ - the rights of one piece of land over another, like a right of way
What is the difference between a deed and a registered title?
Title refers to the ownership of a property - title is land registered witht he land registry.
Deeds is the legal document that transfers title from one person to another. Not registered with land register.
How do you source title information?
I look at the Land Registry
What is an index map?
The index map contains information on all land and property that’s registered or being registered with HM Land Registry. Use it to find the title number of a property that does not appear in a search of the register
What does encryption mean?
Encryption the process of converting information or data into a code, especially to prevent unauthorized access
What is a firewall?
Firewall is software that blocks unexpected connections coming into or out of a network
How can you protect electronic data from viruses?
- Firewall and anti-virus software
- Provide password protection
- Back up your data
- Educate your users on the dangers of viruses
What is data redundancy?
Data redundancy occurs when the same piece of data exists in multiple places
Are electronic signatures accepted by the Land Registry?
From July 2020 – the Land Registry will accept witnessed electronic signatures with immediate effect
What are the penalties for breaching the Data Protection Act (2018)?
Companies will be fined the greater of 4% of annual turnover of £17.5 million
What are the penalties for breach of GDPR?
Fined up to 4% of annual global turnover or £17.5 Million pounds
Under the Data Protection Act how quickly do you need to report a data breach and who to?
Within 72 hours of a personal data breach that causes harm to individuals to the Information Commissioner’s Office
When considering if there is a personal data breach what are the factors you must consider?
You must consider whether there is likely to be:
- physical or material damage
- emotional distress
- embarrassment
What is special category personal data?
sensitive data which needs greater protection as it may cause particular harm or distress if improperly used or disclosed
Can you tell me three principles of UK GDPR and the Data Protection Act 2018?
What is a processor?
A processor is defined as any entity that processes personal data on behalf of the controller.
What is a controller?
A controller is defined as any entity (company or public authority) that determines the purposes and means of the processing of personal data
Give me an example of how you process and handle confidential
information.
- when working on the SFA, I had security clearance to do the work and the information is recieved was strictly confidential. I followed the protocols on not keeping any documents on my personal data, ensuring everything is saved in the secured and protected files.
- I also ensured that after my inspections - all photographs were deleted from my camera
IHT Case
- Don’t print what i don’t need
- Ensure approporiate saving with correct names and conventions
- Dont Leave Computer Unclocked
How do you comply with UK GDPR and the Data Protection Act 2018 in your role?