Data Mangement Flashcards

1
Q

What does confidentiality mean?

A

Information is provided but the topic cannot be shared without permission.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is Meta Data?

A

It is information about a specific piece of data.

E.g. when sharing a valuation report, the meta data would be file size, author and date of creation.

This data must have same level of care as other confidential data.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is intellectual Property and Copyright?

A

The right to control of original work.

When working for an employer, employee work usually belongs to the employer unless copyrights are in place.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is the Freedom of Information Act 2005?

A

UK’s primary legislation controlling access to official information.

Permits public right of access to information held by public authorities.

Information must also be published through the public authorities publication scheme.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is the benefit to using a cloud-based storing system?

A
  • Info is backed up on encrypted servers so is secure
  • Accessibility settings can be managed easily online
  • Cheaper to store than storing documents physically
  • Easier to share files than mailing
  • More environmentally friendly
  • More than one user can access at a time.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is a NDA?

A

Non-Disclosure Agreement

They protect against sharing confidential data

Prior to work being undertaken, client ay request signing of NDA

Can prevent competitors using intellectual property.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What would you do if two rival companies were working with two separate departments in your firm?

A

Make clients aware of the risks to check their understand of COI

Letter of agreement to continue needs to be received from client

Exclusivity of staff would be arranged

May look to use NDA’s

Look to have separate working locations for each team to prevent cross over

Securely store documents so each team had designated store.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Tell me about the Data Protection Act 2018

A

Replaces 1998 legislation and manages how personal data is processed by organisations
and the government.

It is the UK legislation for the implementation of the EU General Data Protection Regulations
(GDPR).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

4 key principles of the Data Protection Act 2018

A

Under the act data is used:

  • Fairly, lawfully and transparently
  • In a way that is adequate, relevant and limited to its intended use
  • Retained for no longer than it is needed
  • Processed securely, protecting against unlawful use and loss or destruction.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What are a person’s rights under the Data Protection Act?

A
  • Be informed on how data being used
  • Right to access their data
  • Right to correct information
  • Right to have data erased
  • Stop or restrict processing of their data
  • Right of portability
  • Object to use of their data.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Key people under GDPR

A

Controller - natural person/ legal entity who determine the processing of personal data
e.g. processing an employee’s personal data, the
employer is considered to be the controller.

Processor - natural person/ legal entity who process data on behalf of the controller
e.g. call centre acting on behalf of its client is the
processor

Data Protection Officer - Leadership role required by EU GDPR. Exists in companies who process personal data of EU citizens. Oversees data protection approach and implementation.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Individual rights under GDPR

A

1) The right to be informed.
2) The right of access.
3) The right of rectification.
4) The right to erasure.
5) The right to restrict processing.
6) The right to data portability.
7) The right to object.
8) Rights of automated decision making and profiling.
9) Diversity, Inclusion & Team Working.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What sources of information do you use within your job?

A
  • Previous tenders
  • RICS Guidance notes
  • Sales information
  • Industry journals
  • Valuation data
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

How do you manage information to ensure compliance with the legislation?

A

Electronic documents are kept securely on encrypted servers, and any physical information is kept locked and secure.

I correctly dispose of confidential documents/ sensitive information

If signed NDA, ensure I do not talk about this work with others not party to the project

Always lock my computer when away from my desk

Regularly attend Cyber security sessions with my work

Regularly update my passwords

If sharing or processing information not available in the public domain from a previous project I
obtain the clients written permission to do so.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Commissioners for Revenue and Customs Act (CRCA) 2005

A

The CRCA is the Act of Parliament that created HM Revenue and Customs in April 2005

Applies to all HMRC and sets out what use HMRC may make of its information and the specific circumstances when we may disclose that information.

Section 18 of CRCA makes clear that you must not give (‘disclose’) HMRC information to anyone, unless you have lawful authority to do so. This includes Other Government Departments and their agencies, local authorities, the police or any other public bodies.

Sections 17, 18 and 20 define when a HMRC member of staff has lawful authority to disclose information. These situations are outlined below.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Which section of the CRCA covers wrongful disclosure?

A

s.19, makes it a criminal offence for VOA employees to disclose information where it identifies a person or allows their identity to be deduced unless:
it is essential for one of our functions
is allowed by a specific piece of legislation e.g. gateway under LGFA
is with the consent of the taxpayer, customer or client
is in the course of civil proceedings e.g. VT hearing

17
Q

What is the statutory deadline for FOI Act response?

A

20 days

(In VOA send to specific FOI inbox on the day received to be dealt with)

18
Q

What is a request for personal information known as under UK GDPR?

A

Subject access request - must be by living individual (no access for executor of deceased’s data, companies have different rights).

19
Q

Which takes precedence of the CRCA and the FOI?

A

Confidentiality of taxpayers information (under CRCA) takes precedence over the right to receive information (under the FOIA).

20
Q

What is the timeline for response on a UK GDPR request?

A

No later than one month from date of receipt.

21
Q

What are the Environmental Information Regulations 2004?

A

Provide public access to environmental information held by public authorities.