Data Management Q's Flashcards
What is GDPR?
- law designed to protect peoples personal data and privacy
- Sets out rules on how governments, companies and organisations can collect, store and use personal information
When did GDPR come into effect?
25th May 2018 - same day is data Protection Act
(Incorporated as part of new EU GDPR legislation)
Who regulates GDPR in the UK?
Information Commissioners Office (ICO)
Key persons outlined in GDPR?
Controller - decides how and why personal data is used
Processor - Handles personal data on behalf of controller
Data officer - Oversees data protection and ensures compliance with rules
What is the purpose of GDPR?
Protect citizens information
What constitutes personal data?
Information that is used to identify a person or data subject e.g photos, names, email address
Examples of personal data under GDPR that could apply to property companies?
Data relating;
- Background checks by HR
- Investors
- Fund managers
- Valuations
- Compliance
What Act implemented GDPR in the UK?
- Data protection Act 2018 - implemented GDPR
- Replaced 1998 Data Protection Act 1998
What are the 7 principles of Data Protection Act 2018? (AKA 7 principles of GDPR) LAAPSID
- Lawfulness, transparency & fairness
- Accountability
- Accuracy
- Purpose Limitation
- Storage Limitation
- Integrity & Confidentiality
- Data minimisation
8 individual rights under GDPR? (IARERDOA)
- Right to be informed
- Right of Access
- Right to Rectfication
- Right to Forgotten
- Right to Restriction Processing
- Right to Data Portability
- Right to Object
- Rights related to Automated Decision making and Profiling
To what organisations does GDPR apply?
Any and all businesses and organisations responsible for holding data in the EU
What are penalties for GDPR breaches?
- Fines of up to 17.5m
- 4% of worldwide turnover
What is the ‘right to access’ under GDPR?
- Right obtain whether their personal data is being processed
- Access to their own personal data that is being held
What is a breach notification under GDPR?
- Formal requirement for organisations (and their data controllers) to notify inform authorities and in some cases individuals if teh breach is likely to risk their rights and freedom
- Need to report 72 hours after becoming aware
How are data breaches typically discovered?
- Automated security systems
- Internal audits
- Lost equipment
How have consent conditions been strengthened under GDPR?
- Consent must given in plain and clear language (best practice to get thsi in writing)
- Ability to withdraw consent at any time
What is ‘right to be forgotten’ under GDPR?
- Under article 17 individuals have right to have personal data erased in certain circumstances
- I.e. if they no longer are employed by a firm
What is data portability?
Right to obtain and reuse personal data across different services or distributed to a new controller
What is privacy by design?
- Legal requirement of GDPR
- data protection from onset in designing systems rather than as addition later on
What is data protection officer?
- They are responsible for monitoring internal compliance and obligations for data protection
- Only required by entities involved in large-scale processing of personal data
Examples of data held by surveying practices?
- Data to serve clients (accounting info, compliance)
- Lease documents
- Emails and other correspondence
What are obligations imposed by GDPR?
- Must be knowledgeable about the data you store (location, security)
- Must be able to be deleted at any time
- Individuals can request to see all their personal data held
- Must demonstrate compliance in data handling
- Must offer data portability
- Must be able to prove how information is being used
RICS best practice points for complying with GDPR?
- Conduct data review
- Anonymise and encrypt data where possible
- Understand data processing
- Treat commercial data in the same as you would treat personal data although it is not covered by GDPR
What are your company’s policies for data protection breaches?
- Report to line manager or data protection officer in firm
- Email GDPR group at Workman
RICS recommendations for using confidential information?
- Keep secure record of consent for data processing
- Maintain confidentiality of information without explicit permission from party
- Check if you have appropriate contractual clauses to use information
What information should be included in firms privacy notice?
- What information you hold
- How will it be used
- How long it will be held for
- Which third parties it will be shared with
- Legal rights