Data Management - Summary of Experience Flashcards

1
Q

What are the penalties under GDPR and data protection act?

A

Fines of higher than 4% of annual turnover or 20m euros (£17.5m)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Can you give me an example of a property information tool?

A
  • Horizon
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are your KPIs for uploading data?

A
  • 7 days from receipt
  • Ensure to keep client informed throughout
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is ISO9001?

A

Sets out requirements for how firms should control data + documents relating to their business

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What would you do if there was a data breach?

A

Report to Information Commissioners office within 72 hours - Notify affected individuals without delay

If within company I would report to line manager/data protection officer

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is the difference between a deed and a registered title?

A

Deed = physical document proving legal ownership
Registered Title = concept of giving right to own electronically

Title takes precedent (it is what the public uses)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is copyright?

A

Type of intellectual property that protects original works and stops others using it

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What does block chain mean?

A

Shared ledger system that facilitates process of recording transactions across a computer network

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is SAR?

A

subject access request
- Individual demands for info a company holds on them

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What are the obligations under GDPR?

A
  • Need to have knowledge of data held and processed
  • Have the ability to delete every instance of data on subject
  • Demonstrate data management compliance
  • Prove how data is used
  • Prove data portability (allow subject to reuse personal data for own purpose)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

How can you protect electronic data from viruses?

A

Antivirus software / firewall / update systems against bugs / strong password

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What are the differences between manual and electronic records?

A
  • Electronic = stored online on file system and can read multiple at once
  • Manual = Physical storage and harder to locate
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is the purpose of GDPR and data protection act?

A

Governs how personal data should be processed + protects rights of individuals

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Explain the growing use of AVMs in the industry

A

Automated valuation models
- Speed, cost and removal of human errors
- Issue is that prop isnt inspected and lack of comparable data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

How can a data breach be discovered?

A
  • Unusual network activity
  • Unauthorised data access attempts
  • Lost equipment
  • Reported thefts
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Are there any disadvantages of the data management systems that you use?

A
  • Updates to ensure strong encryption and firewall - Downtime
  • Always security risk
  • Dependent on internet connections (tech) - If not there data can’t be accessed
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

Can you confirm how data from your examples are stored under the regulations?

A

In line with GDPR principles

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

Can you give me some examples of reports that you run?

A
  • Arrears report
  • Tenancy schedules
  • Service charge analysis
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

What is the right to be forgotten?

A

The right for individuals to have their personal data erased if no longer required or if data processed unlawfully

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

What is a data controller?

A

Determines purposes and means of processing personal data (must comply with principles)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

How did you ensure the data stored for the Ilford High Road sale was safe?

A
  • Disk encryption
  • Firewall and disaster recovery procedures
  • Password protected
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

What is a firewall?

A

Computer network security system that restricts internet traffic

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

Which records are manually kept in your office and why?

A

Financial records e.g. invoices and receipts - Low risk of data loss and provide an audit trail

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

Who is exempt from GDPR?

A
  • National security
  • Journalism
  • Law enforcement
  • Academic research
  • Public health
  • Organisations with fewer than 250 people
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
Q

Can you tell me how CCTV relates to GDPR and the principles that underpin it?

A
  • Data transparency - Lawful/fair
  • Purpose limitation - requires personal data to be collected
  • Storage limitation - Only retained for time period
  • Secured against unauthorised access - data controller etc
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
26
Q

Can you tell me about how you extract data from a source regularly used in your role?

A

Horizon
1) Encrypted login
2) Search up property on system - go to data source needed e.g. invoice
3)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
27
Q

What is an electronic document management system?

A

Software that centrally stores and organises documentation. E.g. Workman EFS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
28
Q

How do you validate information used/received?

A
  • Avoid duplications
  • Cross check against historic data - Tenant/Landlord info
  • Make sure date is complete
  • DI form dates correct - correct charges and sent to correct recipients
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
29
Q

What is the land registry act 2002?

A

Framework to ensure possibility of transferring and creating registered land interests electronically
- Aims to get all freehold land in England and Wales registered by 2030

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
30
Q

What are the key principles of GDPR?

A

1) Lawfulness, fairness and transparency
2) Purpose limitation - specified and explicit
3) Data minimization
4) Accuracy - up to date
5) Storage limitation - should only be kept as long as necessary
6) Integrity and confidentiality
7) Accountability

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
31
Q

What is a data processor?

A

Processes data on behalf of the controller

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
32
Q

What is GDPR?

A

General data protection regulation
- Became EU law in 2016 and UK set up directive in 2018 under Data Protection Act

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
33
Q

What does encryption mean?

A

Converting data into a code to prevent unauthorised access

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
34
Q

When did GDPR come into effect?

A

EU - 25 May 2018

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
35
Q

What are the limitations of secondary data sources?

A
  • No control on what is contained in data
  • Lack of confidence could be wrong and inaccurate - validity
  • above link to GDPR
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
36
Q

How do you comply with GDPR in your role?

A
  • Report breaches
  • Do not give out personal info
  • Keep records of data consent
  • Ensure info held is in line with GDPR
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
37
Q

Can you tell me about the retention of files and limitations act 1980?

A

Sets out how long business should keep documents for. States legal action must be brought within 6 years of issue arising

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
38
Q

What would you do if someone wanted to review the CCTV footage at Merton Road?

A

1) Request received
2) Check with data protection officer
3) Notify police (if required)
4) Ask subject to complete SAR whilst awaiting advice from data protection officer

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
39
Q

What is a data room such as the one you used at 144-146 Ilford High Road?

A

Secure online repository
- Shares sensitive documents
- Controlled access
- Leaves audit trail - When and where users are accessing
- Stored in line with GDPR
- Password protected and encrypted

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
40
Q

Can you give me some examples of data held by surveying practices covered under GDPR?

A
  • Emails/correspondence
  • Customer data held for marketing
  • Data to help service a client (accounting info)
41
Q

What is BIM and how can it be used?

A

Building information modelling
- Generate and manage digital representations of elements of a building e.g. project planning and historic preservation

42
Q

Was the data you mention as part of the data forms held under GDPR regulations?

A

Yes I can confirm

43
Q

Explain how the H&S updates you make ensure you can monitor compliance on Meridian and Quooda?

A
  • Time stamped record of actions completed and comments made
  • See when risk assessments run out - Instruct
  • Green, amber, red - Action tracking system
44
Q

Why was GDPR introduced?

A

To consolidate EU data laws and provide greater protection/rights to individuals

45
Q

What is data management?

A

Practice of collecting, storing and using data securely, efficiently and cost effectively

46
Q

What is the freedom of information act and when did it come into force?

A

Right for anyone to request access to info held by a public body. Public body required to provide within 20 working days (fee can be charged)

  • 30 Nov 2000
47
Q

When was GDPR first introduced?

A

EU in 2016, UK in 2018 under data protection act - UK released own updates in 2021

48
Q

What are the rights of access under GDPR?

A

Individuals have right to access their personal data and supplementary information - can request copy of data free of charge

49
Q

Who regulates GDPR in the UK?

A

Information Commissioners Office

50
Q

How did GDPR tighten up the former data protection act 1998?

A
  • Brought in regulation to cover the development of modern data and technology
  • Stronger consent requirements and also withdrawal of consent
51
Q

Can intellectual property be transferred?

A

Yes - Written agreement e.g. contract/assignment

52
Q

How do you source title information?

A

on gov land registration search

53
Q

What is a data protection officer?

A

Appointed by company if they process large volumes of sensitive data or monitor data subjects (e.g. Workman)

54
Q

What are the limitations of primary data sources?

A
  • Time consuming
  • High cost - e.g. hiring inspectors
  • Human error
55
Q

What are CPSES?

A

Commercial Property Standard Enquiries

56
Q

What is intellectual property?

A

Something that is created using your mind e.g. patent. copyright

57
Q

What constitutes personal data?

A

Any info relating to identified person

58
Q

How do you ensure all data within these examples is kept securely?

A
  • Disk encryption
  • Firewall and disaster recovery procedures
  • Password protected programmes
59
Q

What is your firms data protection policy?

A

That suspected breaches reported to line manager or data protection officer

60
Q

What are the key principles of data processing?

A

1) Lawfulness, fairness, transparency
2) Purpose limitation - only collected for specific purpose
3) Data minimization - only data necessary
4) Storage limitation - minimal time
5) Accuracy - up to date
6) Integrity + confidentiality

61
Q

What platforms did you gather information from?

A
  • Horizon / Sharepoint
  • Emails
62
Q

What is within the RICS guidance for GDPR compliance?

A
  • Document purposes of holding information
  • Keep record of consent for processing, storage and retention
  • Check if you have contract for info
63
Q

What are the individual rights under GDPR and the data protection act?

A

1) Right to be informed
2) Right to access
3) Right to rectification
4) Right to erasure
5) Right to restrict processing
6) Right to data portability
7) Right to object
8) Rights related to automated decision making and profiling

64
Q

What is a data subject?

A

Individual who can be identified by an identifier e.g. name or ID number

65
Q

Who set up the data room at 144-146 Ilford High Road?

A

Solicitors - We get given the passwords to access the data

66
Q

Was the data held at 144-146 Ilford High Road within the same property as the rest of Ilford High Road that you mention?

A

No, my client owned these properties separately, although they were part of the same portfolio

67
Q

How is data managed on the Tramps (Horizon + Sharepoint) platform?

A
  • Collaboration and sharing between different teams within businesses (and between business)
  • Only authorised users can access certain files
  • Audit trails document activity
  • Documents held via the cloud
68
Q

How long can you hold data for?

A

No specified time period - As of GDPR principle should be kept as long as necessary for processing purposes

69
Q

What is hard and soft data?

A

Hard - quantifiable
Soft - not measurable - e.g opinions

70
Q

Explain your use of horizon/tramps and meridian and quooda?

A

Tramps
- Client reporting
- Sending tenant invoices
- Accounting figures for budget
- Legal documentation
- Password protected - change every month

Meridian
- Actioning health and safety queries / documentations
- Prop inspection reports

71
Q

What do the GDPR regulations say about CCTV?

A
  • Reason for surveillance
  • Consider privacy - access/detecting incidents/audit
  • Policies and procedures - what to be recorded/who can view/how long to retain
  • Regular reviews - updated system/cameras added/removed
  • Accountability - Named person (IT team - Data Controller + data protection officer)
  • Need to pay data protection fee to ICO (£2,900 in my case)
  • Register with ICO as CCTV operator
  • Complete a data privacy impact assesment with ICO
72
Q

How did GDPR tighten up the former DPA 1998?

A
  • Customer has greater control over their data
  • Harsh penalties if fail to comply - up to £17.5m or 4% of annual turnover (higher)
  • GDPR is binding piece of legally enforceable regulation
  • Breaches have to be reported to the ICO within 72 hours
  • Companies will be accountable for data protection
  • Firm over 250 people must have dedicated data protection officer
73
Q

RICS best practice points for complying with GDPR?

A
  • Conduct data review
  • Anonymise data where possible
  • Encrypt everything where possible
  • Treat commercial data same as personal data, even though not covered by GDPR
74
Q

What are the exemptions to the Freedom of Information Act?

A

Absolute Exemptions: national security, court records, parliamentary privilege, personal data protected under the data protection act.

Qualified Exemptions: Information that may be withheld if the public interest in maintaining the exemption outweighs the public interest in disclosure.

75
Q

What is the public interest test?

A

Decides under a qualified exemption if it is in the public interest to publish the data

76
Q

How much does it cost to submit a freedom of information request?

A

Can be £0
- Limit is £450 for public authorities
- Limit is £600 for central government

77
Q

How do you ensure accuracy of data?

A
  • Cross-checking
  • Auditing
  • Undertake data reviews
78
Q

Does your firm have a privacy notice? What is included?

A

Yes - It identifies the data controller
- Shows what data is held
- Outlines uses for data
- Outlines how long you hold data for

79
Q

What are the benefits of the cloud?

A
  • Env friendly - less space
  • Speed
  • Accessibility
  • Collaboration
80
Q

What is the difference between the UK Data Protection Act and the rules of GDPR?

A

UK GDPR introduced in 2021, follows similar format of Original EU GDPR

81
Q

When you downloaded the tenants account history reports, how do you ensure that these are stored safely?

A

Stored on electronic filing system (EFS), this is my firms encrypted filing system. I ensured these were saved under property specific folder

82
Q

What was the purpose of contacting the property’s insurers at Merton Road?

A

To see if the insurance for the property allowed this and the potential impact on claims and general insurance premiums

83
Q

What is in a sale checklist like the one you mention at 144-146 Ilford High Road?

A

Ensures correct information is given to buyers of property to avoid claims:
- Lease/legal information
- Property specific information – History of works, health and safety history, historic insurance claims, previous title deeds, EPCS, service charges, utility history, VAT election notice

84
Q

How did you ensure that the folder you set up on your system for the sale ensured data safety principles were met?

A

1) Picked sharepoint as the data room provider - Ensured encryption and password entry
2) Add users - Set boundaries
3) Set permissions for users
4) Add documents and files - These can be downloaded to local internet networks

85
Q

What are CPSEs used for?

A
  • Selling property
  • New lettings
  • Assignments

CPSE 1-3 - New lease
CPSE 2 - Sale
CPSE 4 - Assignment

86
Q

How do you practice handling and managing data in line with GDPR at Workman?

A
  • We have a compliance team and a compliance officer
  • Training provided ie. Cyber training on how to be safe online
  • IT controls on client data, opt in distribution lists etc.
87
Q

What does TRAMPS stand for?

A

Trace Microcomputer Property System

88
Q

How is SAR requested?

A

Can be done in writing/verbally etc

89
Q

What is the difference between the Data Protection Act and GDPR?

A

The Data Protection Act enacts GDRP into UK law

90
Q

Who is the data processor and data controller for the CCTV information?

A

Data processor = security contractor who views and has access to the data
Data controller = Workman as we are defining the means and purposes for holding, using and processing the data

Data is processed on behalf of controller

91
Q

Has your company got any policies regarding document handling?

A

Yes - Traffic light system relating to documents that are held and send

Green - Simple open documents such as blank forms and Workman LLP template forms

Amber - tracked and encrypted documents, usage is tracked, internal docs and emails e.g. tenant financial info, fees, meeting minutes

Red - Confidential docs only accessible for certain few people e.g. completed SAR request forms, internal and external audit findings

92
Q

Where do Workman store their data?

A

On the cloud, which is stored in data centres within the UK.

93
Q

How long does the RICS advise to hold data for?

A

15 years - The Limitations Act 1980 long stop date

94
Q

In your experience, is it better to store data on Workman or Client data systems, why?

A

Conscious some clients are larger institutional funds handling commercially sensitive data and have own requirements and systems
- If using client system - ensure firewall to connect secure locations
- If using Workman system - be aware of client requirements RE password protection, access, location

95
Q

Did you have a pay a fee for the CCTV?

A

Yes we had to pay a data protection fee of £2,900 to the ICO

96
Q

For the sale at 144-146 Ilford High Road, you mention the folder was on your firms internal system, wouldn’t this mean that external visitors could access other files?

A

No, I ensured access restrictions to this individual file, which was confirmed with the IT department, ensuring no 3rd party access to other files

97
Q

What is ISO27001?

A

Set of requirements for defining, implementing, operating, and improving an Information Security Management System (ISMS)
- Proves to customers that it safeguards their data

98
Q

What do ISO27001 users have privilege for?

A

Privileged accounts may access important data or systems or exercise administrative powers.
- It is important to secure privileged accounts to prevent unauthorized use.