Optional - Data Management (L3) Flashcards

1
Q

What is GDPR?

A

GDPR is the General Data Protection Regulation (2016), that came into effect on the 25th May 2018. It aims to create a single data protection regime for the European Union

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What Act Implemented the GDPR in the UK?

A

The Data Protection Act (2018), which replaces the Data Protection Act 1998 after 20 years.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What do you need to do if you have a data breach?

A

Notify the Information Commissioners Office (ICO) within 72 hours of the breach occurring.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are the fines for non-compliance with UK GDPR?

A

For serious breaches of the data protection principles, ICO power to issue fines of up to £17.5 million or 4% of your annual worldwide turnover, whichever is higher

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are the 8 Individual Rights Under GDPR?

A
  1. Right to Be Informed of info being held
  2. Right of Access
  3. Right of Rectification
  4. Right to Erasure
  5. Right to Restrict Processing
  6. Right to Data Portability
  7. Right to Object
  8. Right to Automated Decision Making

BARE ROPA

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

When was the Freedom of Information Act Enforced, and what does it do?

A

The freedom of information Act came into effect in 2000, it allows an individual to request access to information held by a public body. The public body is required to provide that information (normally in 20 working days) in the requested format, however they can charge a fee for this.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Give me an example of how your company is compliant with GDPR

A

On marketing emails, we give people the right to be removed from our database.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Does your company tell people how their data is stored?

A

Yes, our website gives detail on our ‘Fair Processing Notices’ which outlines:
* our purpose of collecting personal data
* how to unsubscribe from marketing communication
* special catergories of data are necessary for fulfilling legal obligations relating to AML

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What Act Implemented the GDPR in the UK?

A

The Data Protection Act (2018), which replaces the Data Protection Act 1998 after 20 years.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is GDPR?

A

GDPR is the General Data Protection Regulation (2016), that came into effect on the 25th May 2018 as part of the UK Data Protection Act.

It aims to create a single data protection regime for the European Union

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What do you need to do if you have a data breach?

A

Notify the Information Commissioners Office (ICO) within 72 hours of the breach occurring.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What are some examples of data security technologies?

A

Disk encryption (encrypting data on a secure hard disk drive)
regular back-ups offsite
password protection
use of anti-virus software protection
firewalls
VPNS (Virtual Private Networks)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is a firewall?

A

Network security device that monitors traffic to or from your network

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is copyright?

A

A set of exclusive rights granted to the author or creator of any original work inc. the right to copy. Form of intellectual property

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is triangulation?

A

Triangulation is the process of verifying data from multiple sources to validate any data collected

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Who polices the Data Protection Act and UK GDPR?

A

Information Commissioners Office (ICO)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

What are the individual rights under UK GDPR? (8)

A
  1. Right to be informed
  2. Right of access
  3. Right to rectification
  4. Right to erasure
  5. Right to restrict processing
  6. Right to data portability
  7. Right to object
  8. Right to automated decision-making and profiling.
18
Q

What are the principles of the UK GDPR? (5)

A

Personal data must be
1. processed lawfully, fairly and in a transparent manner
2. collected for a specific and legitimate purpose
3. accurate and kept up to date
4. kept no longer than necessary
5. processed in a secure manner.

19
Q

What is the link between UK GDPR and Data Protection Act 2018?

A

When UK left EU in 2016, it formed its own regulations, the UK GDPR which is covered by the Data Protection Act 2018

20
Q

What is the aim of the UK GDPR/Data Protection Act 2018?

A

Aims to create a single data protection regime affecting businesses and empowering individuals to take control of how their data is used by third parties

21
Q

What is an SAR?

A

Subject Access Request – Demand that the individual be given all the information that a company holds on them.

22
Q

When was the Freedom of Information Act Enforced, and what does it do?

A

The freedom of information Act came into effect in 2000, it allows an individual to request access to information held by a public body. The public body is required to provide that information (normally in 20 working days) in the requested format, however they can charge a fee for this.

23
Q

What are some of the requirements of the UK GDPR/Data Protection Act 2018? (4)

A
  1. Obligation to conduct data protection impact assessments for high-risk holding of data
  2. Data controllers decides how and why personal data is processed and is directly responsible for GDPR
  3. ‘Data Accountability’ ensures that organisations can prove to the ICO how they comply with the new regulations
  4. Data security breaches need to be reported to the ICO within 72 hours where there is a loss of personal data and a risk of harm to individuals.
24
Q

What is the Freedom of Information Act 2000? (2)

A

Give individuals right of access to information held by public bodies. Public body is required to supply it within 20 working days

25
Q

Are there any exemptions to the Freedom of Information Act 2000? (2)

A
  1. If something is contrary to the UK GDPR
  2. If something would prejudice a criminal matter under investigation.
26
Q

How does an NDA work?

A

legally enforceable contract between two parties relating to sensitive information

27
Q

What is included in an NDA?

A
  1. parties
  2. definition of what is deemed confidential
  3. scope of confidentiality
  4. exclusion of confidentiality
  5. signatures
28
Q

Who is bound by the NDA - the signatory or whole company?

A

Whole company

29
Q

How does your firm keep its data secure?

A
  1. Regular password changes, regular back-ups of site (daily – through ‘OneDrive’)
  2. not allowed external hardware e.g. USB
  3. two-factor authentication and log-in
  4. restricted file access
30
Q

How can you keep a confidential folder safeguarded?

A

Ensure restricted access, use non-descript project names, store properly.

31
Q

How do you ensure accuracy in your data records?

A

Through triangulation - method of verifying data and through regular review. Also restricting access to data controllers

32
Q

What country do you store your data in (and does it matter)?

A

Store in the UK – covered by Data Protection Act 2018 – some countries do not have the same levels of security around data, GDPR etc. outside of the EU for example.

33
Q

Does it make a difference whether a file/folder contains personal data or purely company data?

A
34
Q

How does a virtual data room comply with GDPR Rules?

A
35
Q

How do you shut down a data room securely?

A
36
Q

How do you set up a data room?

A
37
Q

What is leasing velocity?

A
38
Q

What are the limitations of using external databases?

A
  • Can’t always confirm accuracy
  • Can’t always verify source of information
  • Needs to be carefully considered and caveated
39
Q

What are the advantages of external databases?

A
  • Volume of information
  • Quick access to information
  • Cover areas/data you do not personally hold
40
Q

Are there any proposed developments in Data Management for RICS?

A

Proposed RICS Professional Statement on Data Handling and the Prevention of Cyber Crime.

Address how surveyors collect, store and use data.

Address cyber risks posed by modern ways of working including portable devices.

41
Q
A