Data Management - Summary of Experience Flashcards

1
Q

What are the penalties under GDPR and data protection act?

A

4% of annual turnover or 20m euros (£17.5m)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Can you give me an example of a property information tool?

A
  • Horizon
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are your KPIs for uploading data?

A
  • 7 days from receipt
  • Ensure to keep client informed throughout
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is ISO9001?

A

Sets out requirements for how firms should control data + documents relating to their business

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What would you do if there was a data breach?

A

Report to Information Commissioners office within 72 hours - Notify affected individuals without delay

If within company I would report to line manager/data protection officer

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is the difference between a deed and a registered title?

A

Deed = physical document proving legal ownership
Title = concept of giving right to own electronically

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is copyright?

A

Type of intellectual property that protects original works and stops others using it

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What does block chain mean?

A

Shared ledger system that facilitates process of recording transactions across a computer network

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is SAR?

A

subject access request
- Individual demands for info a company holds on them

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What are the obligations under GDPR?

A
  • Need to have knowledge of data held and processed
  • Have the ability to delete data every instance of data on subject
  • Demonstrate data management compliance
  • Prove how data is used
  • Prove data portability (allow subject to reuse personal data for own purpose)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

How can you protect electronic data from viruses?

A

Antivirus software / firewall / update systems against bugs / strong password

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What are the differences between manual and electronic records?

A
  • Electronic = stored online on file system and can read multiple at once
  • Manual = Physical storage and harder to locate
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is the purpose of GDPR and data protection act?

A

Governs how personal data should be processed + protects rights of individuals

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Explain the growing use of AVMs in the industry

A

Automated valuation models
- Speed, cost and removal of human errors
- Issue is that prop isnt inspected and lack of comparable data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

How can a data breach be discovered?

A
  • Unusual network activity
  • Unauthorised data access attempts
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Are there any disadvantages of the data management systems that you use?

A
  • Updates to ensure strong encryption and firewall - Downtime
  • Always security risk
  • Dependent on internet connections (tech) - If not there data can’t be accessed
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

Can you confirm how data from your examples are stored under the regulations?

A

In line with GDPR principles

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

Can you give me some examples of reports that you run?

A
  • Arrears report
  • Tenancy schedules
  • Service charge analysis
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

What is the right to be forgotten?

A

The right for individuals to have their personal data erased if no longer required or if data processed unlawfully

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

What is a data controller?

A

Determines purposes and means of processing personal data (must comply with principles)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

How did you ensure the data stored for the Ilford High Road sale was safe?

A
  • Disk encryption
  • Firewall and disaster recovery procedures
  • Password protected
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

What is a firewall?

A

Computer network security system that restricts internet traffic

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

Which records are manually kept in your office and why?

A

Financial records e.g. invoices and receipts

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

Who is exempt from GDPR?

A
  • National security
  • Journalism
  • Law enforcement
  • Academic research
  • Public health
  • Organisations with fewer than 250 people
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
Q

Can you tell me how CCTV relates to GDPR and the principles that underpin it?

A
  • Data transparency - Lawful/fair
  • Purpose limitation - requires personal data to be collected
  • Storage limitation - Only retained for time period
  • Secured against unauthorised access - data controller etc
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
26
Q

Can you tell me about how you extract data from a source regularly used in your role?

A

Horizon
1) Encrypted login
2) Search up property on system - go to data source needed e.g. invoice
3)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
27
Q

What is an electronic document management system?

A

Software that centrally stores and organises documentation. E.g. Workman EFS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
28
Q

How do you validate information used/received?

A
  • Avoid duplications
  • Cross check against historic data - Tenant/Landlord info
  • Make sure date is complete
  • DI form dates correct - correct charges and sent to correct recipients
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
29
Q

What is the land registry act 2002?

A

Framework to ensure possibility of transferring and creating registered land interests electronically

30
Q

What are the key principles of GDPR?

A

1) Lawfulness, fairness and transparency
2) Purpose limitation - specified and explicit
3) Data minimization
4) Accuracy - up to date
5) Storage limitation - should only be kept as long as necessary

31
Q

What is a data processor?

A

Processes data on behalf of the controller

32
Q

What is GDPR?

A

General data protection regulation
- Became EU law in 2016 and UK set up directive in 2018 under Data Protection Act

33
Q

What does encryption mean?

A

Converting data into a code to prevent unauthorised access

34
Q

When did GDPR come into effect?

A

25 May 2018

35
Q

What are the limitations of secondary data sources?

A
  • No control on what is contained in data
  • Lack of confidence could be wrong and inaccurate - validity
  • above link to GDPR
36
Q

How do you comply with GDPR in your role?

A
  • Report breaches
  • Do not give out personal info
  • Keep records of data consent
  • Ensure info held is in line with GDPR
37
Q

Can you tell me about the retention of files and limitations act 1980?

A

Sets out how long business should keep documents for. States legal action must be brought within 6 years of issue arising

38
Q

What would you do if someone wanted to review the CCTV footage at Merton Road?

A

1) Request received
2) Check with data protection officer
3) Notify police (if required)
4) Ask subject to complete SAR whilst awaiting advice from data protection officer

39
Q

What is a data room such as the one you used at 144-146 Ilford High Road?

A

Secure online repository
- Shares sensitive documents
- Controlled access
- Leaves audit trail - When and where users are accessing
- Stored in line with GDPR
- Password protected and encrypted

40
Q

Can you give me some examples of data held by surveying practices covered under GDPR?

A
  • Emails/correspondence
  • Customer data held for marketing
  • Data to help service a client (accounting info)
41
Q

What is BIM and how can it be used?

A

Building information modelling
- Generate and manage digital representations of elements of a building e.g. project planning and historic preservation

42
Q

Was the data you mention as part of the data forms held under GDPR regulations?

A

Yes I can confirm

43
Q

Explain how the H&S updates you make ensure you can monitor compliance on Meridian and Quooda?

A
  • Time stamped record of actions completed and comments made
  • See when risk assessments run out - Instruct
44
Q

Why was GDPR introduced?

A

To consolidate EU data laws and provide greater protection/rights to individuals

45
Q

What is data management?

A

Practice of collecting, storing and using data securely, efficiently and cost effectively

46
Q

What is the freedom of information act and when did it come into force?

A

Right for anyone to request access to info held by a public body. Public body required to provide within 20 working days (fee can be charged)

  • 30 Nov 2000
47
Q

When was GDPR first introduced?

A

EU in 2016, UK in May 25 2018

48
Q

What are the rights of access under GDPR?

A

Individuals have right to access their personal data and supplementary information - can request copy of data free of charge

49
Q

Who regulates GDPR in the UK?

A

Information Commissioners Office

50
Q

How did GDPR tighten up the former data protection act 1998?

A
  • Brought in regulation to cover the development of modern data and technology
  • Stronger consent requirements and also withdrawal of consent
51
Q

Can intellectual property be transferred?

A

Yes - Written agreement e.g. contract/assignment

52
Q

How do you source title information?

A

on gov land registration search

53
Q

What is a data protection officer?

A

Appointed by company if they process large volumes of sensitive data or monitor data subjects (e.g. Workman)

54
Q

What are the limitations of primary data sources?

A
  • Time consuming
  • High cost - e.g. hiring inspectors
  • Human error
  • GDPR?
55
Q

What are CPSES?

A

Commercial Property Standard Enquiries

56
Q

What is intellectual property?

A

Something that is created using your mind e.g. patent. copyright

57
Q

What constitutes personal data?

A

Any info relating to identified person

58
Q

How do you ensure all data within these examples is kept securely?

A
  • Disk encryption
  • Firewall and disaster recovery procedures
  • Password protected programmes
59
Q

What is your firms data protection policy?

A

That suspected breaches reported to line manager or data protection officer

60
Q

What are the key principles of data processing?

A

1) Lawfulness, fairness, transparency
2) Purpose limitation - only collected for specific purpose
3) Data minimization - only data necessary
4) Accuracy - up to date
5) Storage limitation - minimal time
6) Integrity + confidentiality

61
Q

What platforms did you gather information from?

A
  • Horizon / Sharepoint
  • Emails
62
Q

What is the RICS guidance for GDPR compliance?

A
  • Document purposes of holding information
  • Keep record of consent for processing, storage and retention
  • Check if you have contract for info
63
Q

What are the individual rights under GDPR and the data protection act?

A

1) Right to information
2) Right to access
3) Right to rectification
4) Right to erasure
5) Right to restrict processing
6) Right to data portability
7) Right to object
8) Right to automated decision making

64
Q

What is a data subject?

A

Individual who can be identified by an identifier e.g. name or ID number

65
Q

Who set up the data room at 144-146 Ilford High Road?

A

Solicitors

66
Q

Was the data held at 144-146 Ilford High Road within the same property as the rest of Ilford High Road that you mention?

A

No, my client owned these properties separately, although they were part of the same portfolio

67
Q

How is data managed on the Tramps (Horizon + Sharepoint) platform?

A
  • Collaboration and sharing between different teams within businesses (and between business)
  • Only authorised users can access certain files
  • Audit trails document activity
68
Q

How long can you hold data for?

A

No specified time period - As of GDRP principle should be kept as long as necessary for processing purposes

69
Q

What is hard and soft data?

A

Hard - quantifiable
Soft - not measurable - e.g opinions

70
Q

Explain your use of horizon/tramps and meridian and quooda?

A

Tramps
- Client reporting
- Sending tenant invoices
- Accounting figures for budget
- Legal documentation
- Password protected - change every month

Meridian
- Actioning health and safety queries / documentations
- Prop inspection reports