Data Management - Summary of Experience Flashcards
What are the penalties under GDPR and data protection act?
Fines of higher than 4% of annual turnover or 20m euros (£17.5m)
Can you give me an example of a property information tool?
- Horizon
What are your KPIs for uploading data?
- 7 days from receipt
- Ensure to keep client informed throughout
What is ISO9001?
Sets out requirements for how firms should control data + documents relating to their business
What would you do if there was a data breach?
Report to Information Commissioners office within 72 hours - Notify affected individuals without delay
If within company I would report to line manager/data protection officer
What is the difference between a deed and a registered title?
Deed = physical document proving legal ownership
Registered Title = concept of giving right to own electronically
Title takes precedent (it is what the public uses)
What is copyright?
Type of intellectual property that protects original works and stops others using it
What does block chain mean?
Shared ledger system that facilitates process of recording transactions across a computer network
What is SAR?
subject access request
- Individual demands for info a company holds on them
What are the obligations under GDPR?
- Need to have knowledge of data held and processed
- Have the ability to delete every instance of data on subject
- Demonstrate data management compliance
- Prove how data is used
- Prove data portability (allow subject to reuse personal data for own purpose)
How can you protect electronic data from viruses?
Antivirus software / firewall / update systems against bugs / strong password
What are the differences between manual and electronic records?
- Electronic = stored online on file system and can read multiple at once
- Manual = Physical storage and harder to locate
What is the purpose of GDPR and data protection act?
Governs how personal data should be processed + protects rights of individuals
Explain the growing use of AVMs in the industry
Automated valuation models
- Speed, cost and removal of human errors
- Issue is that prop isnt inspected and lack of comparable data
How can a data breach be discovered?
- Unusual network activity
- Unauthorised data access attempts
- Lost equipment
- Reported thefts
Are there any disadvantages of the data management systems that you use?
- Updates to ensure strong encryption and firewall - Downtime
- Always security risk
- Dependent on internet connections (tech) - If not there data can’t be accessed
Can you confirm how data from your examples are stored under the regulations?
In line with GDPR principles
Can you give me some examples of reports that you run?
- Arrears report
- Tenancy schedules
- Service charge analysis
What is the right to be forgotten?
The right for individuals to have their personal data erased if no longer required or if data processed unlawfully
What is a data controller?
Determines purposes and means of processing personal data (must comply with principles)
How did you ensure the data stored for the Ilford High Road sale was safe?
- Disk encryption
- Firewall and disaster recovery procedures
- Password protected
What is a firewall?
Computer network security system that restricts internet traffic
Which records are manually kept in your office and why?
Financial records e.g. invoices and receipts - Low risk of data loss and provide an audit trail
Who is exempt from GDPR?
- National security
- Journalism
- Law enforcement
- Academic research
- Public health
- Organisations with fewer than 250 people
Can you tell me how CCTV relates to GDPR and the principles that underpin it?
- Data transparency - Lawful/fair
- Purpose limitation - requires personal data to be collected
- Storage limitation - Only retained for time period
- Secured against unauthorised access - data controller etc
Can you tell me about how you extract data from a source regularly used in your role?
Horizon
1) Encrypted login
2) Search up property on system - go to data source needed e.g. invoice
3)
What is an electronic document management system?
Software that centrally stores and organises documentation. E.g. Workman EFS
How do you validate information used/received?
- Avoid duplications
- Cross check against historic data - Tenant/Landlord info
- Make sure date is complete
- DI form dates correct - correct charges and sent to correct recipients
What is the land registry act 2002?
Framework to ensure possibility of transferring and creating registered land interests electronically
- Aims to get all freehold land in England and Wales registered by 2030
What are the key principles of GDPR?
1) Lawfulness, fairness and transparency
2) Purpose limitation - specified and explicit
3) Data minimization
4) Accuracy - up to date
5) Storage limitation - should only be kept as long as necessary
6) Integrity and confidentiality
7) Accountability
What is a data processor?
Processes data on behalf of the controller
What is GDPR?
General data protection regulation
- Became EU law in 2016 and UK set up directive in 2018 under Data Protection Act
What does encryption mean?
Converting data into a code to prevent unauthorised access
When did GDPR come into effect?
EU - 25 May 2018
What are the limitations of secondary data sources?
- No control on what is contained in data
- Lack of confidence could be wrong and inaccurate - validity
- above link to GDPR
How do you comply with GDPR in your role?
- Report breaches
- Do not give out personal info
- Keep records of data consent
- Ensure info held is in line with GDPR
Can you tell me about the retention of files and limitations act 1980?
Sets out how long business should keep documents for. States legal action must be brought within 6 years of issue arising
What would you do if someone wanted to review the CCTV footage at Merton Road?
1) Request received
2) Check with data protection officer
3) Notify police (if required)
4) Ask subject to complete SAR whilst awaiting advice from data protection officer
What is a data room such as the one you used at 144-146 Ilford High Road?
Secure online repository
- Shares sensitive documents
- Controlled access
- Leaves audit trail - When and where users are accessing
- Stored in line with GDPR
- Password protected and encrypted