Data Mangement Flashcards
What is GDPR?
EU General Data Protection Regulation
What Act implemented GDPR in the UK
Data Protection Act 2018
When was GDPR effective from
25th May 2018
What is the purpose of GDPR?
Protect citizens personal data
What constitutes personal data?
Any information related to a person that can be used to identify a person eg names, photos, email address, bank details
Examples of personal data under GDPR that could apply to property companies
- property performance/investor data
- fund managers
- tenant data
- valuations
- compliance
- background checks completed by HR
to what organisations does GDPR apply
all organisations greater than 250 employees
What are the penalties for GDPR breaches?
Up to 20 million Euros
OR
4% of annual global turnover
Whichever is greater
what is the ‘right to access’ under GDPR
Individuals have the right to obtain confirmation that their data is being processed and access to their personal records.
What are the timeframes to publish a breach notification under GDPR
- Need to report the breach within 72 hours of becoming aware of breach to Information commissions office (ICO)
- if breach is high risk, then notify individuals without delay
How are data breaches typically discovered?
- Data security incident
- Access logs
- Reported thefts
- Lost equipment
how has consent condition been strengthened under GDPR
- consent must be given using plain and clear language
- Must be as easy to withdraw consent as it is to give it
What is ‘right to be forgotten’ under GDPR
- Article 17 GDPR, individuals have right to have personal data erased in certain circumstances:
- data no longer necessary
- data been processed unlawfully
What is data portability?
- right for data subject to receive personal data concerning them which they have previously provided, and have it transmitted to another controller
What is privacy by design?
- Legal requirement under GDPR
- inclusion of data protection from outset, rather than as addition