Data managment Flashcards

1
Q

What is GDPR and what are its principles?

A

EU legislation to strengthen individual rights over their personal data.

Applies to all personal data, seven key principles

  1. Lawfulness, fairness and transparency
  2. Purpose limitation
  3. Data minimisation
  4. Accuracy
  5. Storage limitation
  6. Integrity and confidentiality
  7. accountability
  8. not to be transfer to countries with different protection
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What must companies put in place to ensure compliance with GDPR?

A

-data protection policy
-staff training
-lawful basis for processing
-privacy notice
-security measures
-data protection officer

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Why is it important to limit access to personal data?

A

-protect individuals data
-reduce risk of breach
-data minimisation
-demonstrate accountability

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

How is information stored securely in your firm?

A
  • cloud based system
  • password protected folders and limited access
    -firewall
    -eg mindcast softwear
    -quarentine page
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are the personal rights in regards to data?

A

-access
-request correction
-request erasure
-restrict processing
-object to process
-data portability

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

How do you verify your data source eg for comparable valuation?

A

-check with agents

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Who are the key persons involved in GDPR?

A

-controller
-professor
-data subject

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Who is the data controller in your firm?

A

Director

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What must you do if there is a data breach?

A

Inform ICO within 72 hours, when data lost and risk involved

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What are the penalties for a data breach?

A

4% of global annual turnover or 20m euros

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is the Data protection act 2018?

A

The data protection act sets out how personal data should be processed and protects individual privacy rights

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What does article 5 of GDPR 18 - key principles?

A
  1. lawfully, fairly and transparently (LAS)
  2. purpose of limitation
  3. data minimisation
  4. Accuracy
  5. storage limitations
    6.securely
    7.accountability
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What are individuals rights under GDPR18?

A
  1. Access
  2. restrict Processing
  3. data Portability
  4. Erasure
  5. relation to Automated decision making and profiling
  6. Rectification
  7. be Informed
  8. Object
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is a subject data request?

A

individuals right to access personal data that an organisation holds about them

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What would you do if a date breach occurred?

A

Data breaches must be reported to the Information Commissioner’s Office (ICOs) within 72 hours of discovery. The ICO is the UK’s independent body responsible for enforcing information rights. The ICO has the power to issue fines for non-compliance which can reach up to £17.5 million or 4% of global annual turnover

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

what is the freedom of information act 2000?

A

-An individual has a right to access information held by a public body. Aim is to improve transparency and accountability

-When requested the body aims to release the information within 20 days and can charge a fee for disclosure

17
Q

What legislation do you adhere to when handling data?

A

Data protection act 2018 (UK) and general data protection 2018 (EU)

18
Q

What is copy right?

A

-set of exclusive rights granted to the author or creator of original work, including the right to copy

-rights can be licensed, assigned or transferred
-form of intellectual property
-must acknowledge copyright for info duplicated in work

19
Q

What is intellectual property and can it be transferred?

A

Intellectual Property (IP) refers to creations of the mind that are legally protected, allowing individuals or businesses to control how their ideas, inventions, or creative works are used. It gives the owner exclusive rights over their work. E.g. patents, or trademarks

20
Q

Tell me about the Retention of Files and Limitation Act 1980?

A

Sets out the time limits within which legal actions can be taken. Keep documents for 6 years, however some are more eg deed 12 years, then correctly disposed.

21
Q

What are the General Data Protection Regulations?

A

EU legislation to strengthen individual rights over their personal data. Applies to all personal data, seven key principles

22
Q

What are the disadvantages of using systems like CoStar, Rightmove etc?

A

-not always accurate
-need to verify it directly with the agent which can sometimes be challenging

23
Q

What is your company’s Asset Management Plan?

A

Documentation which collected all property and tenancy information onto one document

reviewed yearly and shows growth or decline over 5 year period

24
Q

How do you ensure this data is accurate?

A

carefully collected, and checked by a colleague

25
Q

How do you ensure that it complies with Data Protection laws?

A

only collect for purpose and store for as long as required

26
Q

What is your company’s data management policy?

A

6 years unless its personal data

27
Q

Who audits the data that is stored on your system?

A

For commercial department its the compliance manager

28
Q

what are the penalties for breach of the Data Protection Act?

A

4% of global profit or 20M euro

29
Q

To whom would you report a breach of personal data to?

A

Internally out Data officer, who would report it to the ICO

30
Q

what is considered personal and sensitive data?

A

Personal: identifies individual directly or indirectly

Sensitive: health, race, religion etc

31
Q

How do you comply with your firms data management policy?

A

-only collect and store data with a purpose and time
-frequently change passwords
-don’t leave devices unattended

32
Q

What training have you received on data management?

A

annual internal training on data protection policies

33
Q

Difference between direct and in-direct?

A

Direct - one piece fo data can identify someone eg name, number

Indirect - combo to identify someone, eg DOB, postcode

34
Q

UK General Data Protection Regulations

A

as EU doesn’t apply, essentially transcribed into UK GDPR
-UK GDPR covers data protection act 2018

-aim to create single data protection regime

35
Q

Key requirements for data protection act?

A

-obligation to conduct data protection impact assessment for high risk holding of data
-new rights for individuals to access info and have it erased
-data controller
-report to ICO in 72 hours

36
Q

What is article 5 (2)?

A

requires data controller responsible for and able to demonstrate compliance with principles

37
Q

How can security of data be improved?

A

-firewall
-encryption
-cloud-based
-2 step verification
-NDA

38
Q

What is your firms data retention policy?

39
Q

What counts as personal data?

A

such as name, DOB, address, email address