General Flashcards
How long do you need to keep data for?
6 years if contract signed under hand
12 years if under deed
RICS recommends up to 15 years, this is the limitation period for most legal claims
Type of data systems your company uses?
Shared hard drives
Back up servers
Software such as teams
What are the aims of the GDPR?
Gives the public a say on what is done with their personal information
GDPR was aimed at protecting all EU citizens from privacy and data breaches
What is the Data Protection Act 2018?
It gives individuals the right to know what information is held about them and provides a framework to ensure that it’s handled properly.
What is meant by penalties regarding GDPR?
4% of companies global turnover or £20m if GDPR is breached
What challenges does the Data Protection Act pose?
Multiple users on systems
Saving files in incorrect locations
Server breakdown causing work or data to be lost
How is the GDPR relevant in your day to day work?
I manage high amounts of sensitive data and this needs to be done in line with the data protection act and GDPR.
What should companies have in place in regard to data protection?
Companies should employ a data protection officer, make sure they comply with all the data protection policy and be clear and transparent when talking about data.
How do you ensure that you comply with data protection legislation?
I store and keep confidential information in line with Gleeds’ policy and maintain the clear desk policies on a daily basis
What is the Freedom of Information Act 2000?
The Act provides individuals or organisations with the right to request information
What data do you use in your work and how do you manage this?
Consider any data you collect such as financial figures, valuation figures, contact details, etc. and be able to explain how you ensure this complies with the legislation.
What types of data is considered under GDPR
Any personal data including:
Name
Religion
Sexual orientation
Trade union membership
Physical or mental health
Genetic data
What must you do if you accidentally breach GDPR and send information to the wrong person?
Report to your data protection officer who will then report it to ICO regulator
What is submitted to BCIS?
Project type
Time it was undertaken
Costs
Programme
What might your organisation keep hard copies of?
Books
Contracts
Tender documents
Design drawings
What is a project extranet?
An electronic system in which project information can be distributed to the relevant parties, which is a secure way to collaborate
What are the advantages and disadvantages of a project extranet?
Advantages include:
- Improves communication
- Accessible 24 hours per day
- Efficient
- Secure
Disadvantages:
- Can be expensive (subscription)
- Requires maintenance
- May require user training
What is the purpose of GDPR?
Harmonise data privacy laws across all members of the EU and EEA, providing greater protection for individuals
Also addresses how business can handle information of those who interact with them
Who are the key people named under GDPR?
Data Subject: who the data is about
Data Processor: who processes the data (such as assistant to the data controller)
Data Controller: deals with how and why the data has been collected / is being used
Data Protection Officer: implements the data protection regulations
What constitutes personal data under GDPR?
Name
Photo
Email
Bank details
Medical information
What are the 7 key principles under GDPR?
Lawfulness, fairness & transparency
Accountability
Data minimisation
Storage limitation
Purpose limitation
Accuracy
Confidentiality & Integrity
What are the 8 individual rights under GDPR?
The right….:
1. To be informed
2. To Erasure
3. To rectification
4. To access
5. To data portability
6. To object
7. To automated decision making & profiling
8. To restrict processing
Who enforces GDPR?
The information commissioners office
Can you tell me the difference between an intranet and an extranet
Intranet = private network for employees to communicate and collaborate internally within an organisation
Extranet = private network outside of a company that allows authorised users to access, communicate and collaborate