Data Protection Flashcards

1
Q

What is GDPR?

A

Legislation that governs how companies handle personal data [in the EU].

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are the key principles of GDPR (7)?

A
  • Lawfulness, fairness and transparency.
  • Purpose limitation (data shouldn’t be use for other purposes than originally intended).
  • Data minimisation (data should be collected for specific purpose).
  • Accuracy.
  • Storage limitation (shouldn’t be kept for longer than necessary).
  • Integrity and confidentiality (security)
  • Accountability.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Through which piece of legislation are the General Data Protection Regulations (GDPR) implemented?

A

The Data Protection Act 2018.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Can you name 3 of the 8 principles of the Data Protection Act 2018?

A

ASS.
- Accuracy: Personal data must be accurate [and kept up to date].
- Storage: Personal data shouldn’t be kept longer than necessary.
- Security: Personal data must be kept secure.

  • Fairly and lawfully processed.
  • Purpose.
  • Adequacy.
  • Accuracy.
  • Storage.
  • Rights.
  • Security.
  • International transfers.

[- Fairly and lawfully processed: Personal data must be processed fairly and lawfully.
- Purpose: Personal data must be obtained for one or more specified and lawful purpose.
- Adequacy: Personal data must be relevant and not excessive.
- Accuracy: Personal data must be accurate and kept up to date.
- Storage: Personal data must not be kept longer than is necessary.
- Rights: Right to see any data held on you [and to correct inaccurate data].
- Security: Personal data must be kept secure.
- International transfers: Personal data must not be transferred to other countries outside the European Economic Area, unless those countries have similar data protection laws.]

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

How long should a firm hold a client’s data for following completion of an instruction?

A
  • Min 6 years from when the incident occurred.
  • 12 years for some instructions (projects – 12 deed limitation period).
  • 15 years to protect against negligence claims.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Who should data breaches be reported to?
When does this need to be reported?

A
  • Information Commissioner’s Office (ICO).
  • Data protection officer.
  • Within 72 hours.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

How does your company securely store data?

A
  • Cloud storage.
  • Encrypted.
  • VPN.
  • Passwords.
  • Two-factor authentication.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Is there any legislation or legal process your company will follow for data?

A
  • Data Protection Act 2018.
  • GDPR.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Can you provide an example of a legal requirement that your company will have to follow regarding data?
What GDPR principle does that relate to?

A
  • Someone can request a copy of their data (Subject Access Request).
  • Right of access.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

How do you verify your data?

A
  • Use reliable sources e.g. land registry.
  • Cross reference with other sources
  • Confirm information with client.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

How does your treatment of data comply with current legislation?

A
  • Personal data kept securely.
  • Provide personal data held on request (SAR).
  • Client data kept for 6 years (underhand)/12 years (deed) [from when the incident occurred].
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is meant by Article 5 of GDPR when it says ‘kept in a form that permits identification of data subjects for no longer than is necessary’? How is this relevant to your role?

A
  • You’re not allowed to hold personal information for longer than necessary i.e. contact information.
  • Relevance: information has to be archived after a certain period (6 years/12 years).
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Why do you think data you hold needs to be accurate?

A
  • To comply with GDPR [Article 5].
  • States personal data must be accurate or deleted.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What are the consumer rights under GDPR?

A
  • Access (SAR) [right of].
  • Erasure [right of].
  • Rectification [right to].
  • Informed [right to be].
  • Object [right to].
  • Restriction of processing [right to].
  • Data portability [right to].
  • Rights related to automated decision-making and profiling.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is the definition of personal data?

A

Information relating to an identifiable person.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What would constitute a security breach?
What is your company policy on reporting a breach?
How long do you have to report it to ICO (Information Commissioner’s Office)?

A
  • Losing confidential files, stolen laptop.
  • Notify affected parties [and describe the impact].
  • Must notify the ICO within 72 hours of becoming aware of breach.
17
Q

How long should you keep deeds on file?

A

Minimum of 15 years.
[Claim of negligence can be made up to 15 years after the negligent act occurred].

18
Q

What are the penalties for a data breach?

A
  • Fine (from ICO - enforced under DPA 2018).
  • Discplinary action.
    [RICS - breach of ROC (competence, acting with integrity)].
    [Could lead to formal investigation, suspension or expulsion from RICS].
19
Q

If servers are kept abroad does the Data Protection Act apply?

A

Yes, if you process personal data in the UK then DPA 2018 and GDPR applies no matter where the servers are located.