Data Mangement Flashcards

1
Q

What is GDPR?

A

EU General Data Protection Regulation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What Act implemented GDPR in the UK

A

Data Protection Act 2018

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

When was GDPR effective from

A

25th May 2018

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is the purpose of GDPR?

A

Protect citizens personal data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What constitutes personal data?

A

Any information related to a person that can be used to identify a person eg names, photos, email address, bank details

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Examples of personal data under GDPR that could apply to property companies

A
  • property performance/investor data
  • fund managers
  • tenant data
  • valuations
  • compliance
  • background checks completed by HR
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

to what organisations does GDPR apply

A

all organisations greater than 250 employees

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What are the penalties for GDPR breaches?

A

Up to 20 million Euros
OR
4% of annual global turnover
Whichever is greater

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

what is the ‘right to access’ under GDPR

A

Individuals have the right to obtain confirmation that their data is being processed and access to their personal records.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What are the timeframes to publish a breach notification under GDPR

A
  • Need to report the breach within 72 hours of becoming aware of breach to Information commissions office (ICO)
  • if breach is high risk, then notify individuals without delay
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

How are data breaches typically discovered?

A
  • Data security incident
  • Access logs
  • Reported thefts
  • Lost equipment
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

how has consent condition been strengthened under GDPR

A
  • consent must be given using plain and clear language
  • Must be as easy to withdraw consent as it is to give it
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is ‘right to be forgotten’ under GDPR

A
  • Article 17 GDPR, individuals have right to have personal data erased in certain circumstances:
  • data no longer necessary
  • data been processed unlawfully
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is data portability?

A
  • right for data subject to receive personal data concerning them which they have previously provided, and have it transmitted to another controller
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is privacy by design?

A
  • Legal requirement under GDPR
  • inclusion of data protection from outset, rather than as addition
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

what is a data protection officer

A
  • An individual appointed to monitor internal compliance, stategy and implementation of GDPR
17
Q

Examples of data held by surveying practices

A
  • HR/Payroll
  • customer data for marketing
  • Emails and correspondence relating to clients, tenants, employees, contractors.
18
Q

What are obligations imposed by GDPR?

A
  • knowledge of data you store and process
  • Keep data in format that allows portability to another data processor, should the need arise
  • Demonstrate data is being managed in compliant manner
  • Delete every instance of an individuals data in compliance with ‘right to be forgotten’
  • Provide information on how data is used and the rights of individuals
19
Q

who regulates in the UK?

A

Information Commissioners Office

20
Q

RICS best practice points for complying with GDPR?

A
  • conduct data review
  • anonymise data where possible
  • encrypt everything where possible
  • treat commercial data in same way as personal data, even though not covered by GDPR
21
Q

What are your companies policies for data protection breaches?

A

report to line manager AND/OR Data protection officer

22
Q

RICS recommendations for using confidential information

A
  • Document purposes for which you are allowed to hold information
  • Keep record of consent
  • check contractual clauses
23
Q

What information should be included in firms privacy notices?

A
  • what information you have
  • what information will be used for
  • which 3rd parties may have access to the data
  • how long information will be stored
  • what legal rights they have
24
Q

What are the 7 principles of Data Protection Act 2018 (GDPR)

A
  • lawfulness, fairness and transparency
  • Accuracy
  • Accountability
  • Purpose limitation
  • storage limitation
  • data minimisation
  • integrity and confidentiality
25
Q

What are the 8 individual rights under GDPR

A

Right to:
- information
- Access
- Erasure
- object
- Rectification
- Data portability
- Restricted data processing
- automated decision making

26
Q

What is SAR

A

Subject Access Rights

Demand that the individual be given all the information that a company holds on them

27
Q

What was the freedom of information Act?

A
  • come in effect in 2000
  • allows an individual to request access to information held by a public body
  • public body is required to provide that information in requested format
  • they can charge a fee for this
28
Q

what are the provisions of the Land Registry Act 2002?

A
  • Provides a complete and accurate reflection of the state of the title of land
  • aim is to get all freehold land in England and wales registered by 2030
29
Q

Disadvantages of the system you use?

A
  • rely on data input completed by others (human error)
  • external systems - firms is not in control of security
  • not user friendly and lots of staff training required
30
Q

What were the changes as a result of GDPR

A
  • customer has greater control
  • Harsher penalties
  • Legally enforceable
  • Applies to all EU nations
  • Breaches reported in 72 hours
  • companies accountable for data protection
  • any firm with over 250 employees accountable.
31
Q

Name some data security technologies

A
  • Disk encryption - encrypt data on secure hard drive disk
  • Regular back-ups off site
  • Password protection
  • Use of anti-virus software protection
  • Firewalls and disaster recovery procedures
32
Q

What is copy right?

A

Set of exclusive rights given to an author or creator for an original piece of work. It is seen as a form of intellectual property