Optional - Data Management (L3) Flashcards

1
Q

What is the Data Protection Act 2018?

A
  • UK’s implementation of the General Data Protection Regulation 2016 (GDPR)
  • Complete data protect system – as well as governing personal data covered by GDPR, it covers all other general data as previously covered by the 1998 Act
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is GDPR?

A
  • General data protection regulation
  • Relates to personal data
  • Aims to create a single data protection regime for anyone doing business in the EU and to empower individuals to take control of how their data is used by third parties
  • Gives people stronger rights to be informed about how their personal information is used
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are the key requirements under GDPR?

A
  • Obligation to conduction data protection impact assessments for high risk holding of data
  • New rights for individuals to have access to information on what personal data is held and to have it erased
  • A data controller decides how and why personal data is processed and is directly responsible for GDPR
  • Data accountability’ ensuring that organisations can prove to the Information Commissioners Office (ICO) how they comply with the new regulations
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What happens if you breach GDPR? What is the penalty?
Who polices it?

A
  • Data security breaches need to be reported to Information Commissioners Office (ICO) within 72 hours where there is a loss of personal data and a risk of harm to individuals
  • An increase in fines up to 4% global turnover of the company or £17.5m (whichever is the greater)
  • Policed by the ICO
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

How has your firm changed their data management practices to comply with GDPR?

A
  • Ensure data accountability through the appointment of a named data controller
  • Trained staff
  • Ensured firewalls on employees data
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Under GDPR, would you be able to transfer personal data you hold outside of the UK?

A

Yes, but only if you ensure that the destination country or organisation provides an adequate level of protection for the data — similar to what the UK law requires

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is the Freedom of Information Act 2000?

A

Gives individuals the right of access to information held by public bodies

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What does the Freedom of Information Act 2000 require of public bodies?

A
  • Public body must tell any individual requesting sight of information whether it holds it
  • Normally the public body is required to supply it in 20 working days in the format requested
  • It can charge for the provision of the information
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What are the exemptions from the Freedom of Information Act 2000?

A
  • Public interest test - is it better for the public to know this? I.e GDPR, Criminal, National Sec
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What are the elements of a Non-Disclosure Agreement (NDA)?

A
  • Identification of the parties
  • Definition of what is deemed to be confidential
  • Scope of the confidentiality obligation by the receiving party
  • The exclusions from confidential treatment
  • The length of term of the agreement
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What are automated valuation models (AVMs)?

A
  • Software systems which can provide property valuations using mathematical modelling combined with a database
  • They are most used for residential property
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What do you understand by the term security of data?

A

Means ensuring that data is kept safe from corruption and that access to it is suitably controlled to ensure privacy and protection

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

How can security of data be improved? (5)

A
  • Message encryption
  • Back ups to hard drives
  • Password protection
  • Use of anti-virus software protection
  • Firewalls and disaster recovery procedures
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What does copyright mean?

A
  • A set of exclusive rights granted to the author or creator of any original work, including the right to copy
  • These rights can be licensed, assigned or transferred
  • Form of intellectual property
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is a deed?

A

A legal document made under seal

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What do the Land Registry provide upon request and payment?

A

Copy of the official Title Register for registered property or land in the UK

17
Q

What does Title indemnity insurance cover?

A
  • Protects a party for any claim arising from the title of a property e.g. title defects, restrictive covenants and easements
  • Paid as a one-off premium
18
Q

What are MSCI Real Estate indices?

A

• Indices which provide investment performance statistics for owners and investors / fund management

19
Q

What do MSCI Real Estate indices aim to provide?

A
  • Independent benchmarks and market data
  • Provide real estate performance analysis, market indices and research regarding property investment performance and risk to the real estate world
20
Q

How do the MSCI produce their Real Estate indices?

A

Draw on up-to-date valuations of selected UK properties

21
Q

What are the RICS Data Standards, 2018?

A

Help professionals in the property and real estate sectors manage and use data in a consistent, accurate, and trustworthy way

22
Q

What does the colour coding on Title Plans represent?

A
  • Red Line – boundary of registered land
23
Q

What is included in a Land Registry title register?

A
  • A: Property register - description of the property, tenure, the date the property was first registered and any rights it may benefit from e.g. private right of way
  • B: Proprietorship register - name and address of the current owner, when they bought the property, how much was paid for it (if sold since 1 April 2000), any restrictions that limit the power of the owner and the class of the title
  • C: Charges register - mortgages and other financial burdens received on the property. Other rights or interest that limit how the land or property can be used e.g. leases, rights of way or covenants
24
Q

What is a SAR?

A
  • Subject access request

* Gives individuals rights to request any ‘personal data’ held on them.

25
What is "personal data" as defined by GDPR?
Personal data are any information which are related to an **identified** or **identifiable** natural person e.g. the telephone number, email address
26
What will be contained in the professional statement on Data Handling and Prevention of Cybercrime , 2020?
* Best practice and 24 mandatory obligations * It will sit behind the legal requirements of the Data Protection Act 2018 in the UK
27
Who do you notify if you have a data breach?
ICO - within 72 hours
28
# UPRR AMBP What are the principles of Data Protection Act 2018?
U - UK’s Implementation of GDPR (Under Pressure - they have to implement and enforce the law) P - Principles (Responsible - referring to acting lawfully, fairly, transparently, etc.) R - Rights (Regulators - ensuring individuals’ rights are protected) R - Requires Consent (Always - emphasising the requirement for consent) A - Applies to Personal and Sensitive Data (Applies - broad coverage of data types) M - Mandates DPOs (Manage - Data Protection Officers managing large-scale processing) B - Breach Notification (Breaches - must be reported within 72 hours) P - Penalties (Properly - emphasizing the strict enforcement and penalties)
29
Give me an example of how your company is compliant with GDPR
* When we send out marketing emails to prospective purchasers, we send emails individually rather en masse * On marketing emails, we give people the right to be removed from our database * Privacy notice when we collect data * Fair Processing Notice on website * 2FA and encryption
30
Who is responsible?
Data Protection Officer
31
Right to Individuals under UK GDPR (DEAARRIO)
1) D – Data portability 2) E – Erasure 3) A - Access 4) A – Automated decision making and profiling 5) R – restrict processing 6) R – Rectification 7) I – informed 8) O – object
32
7 Policies/ Principles: (LIPSAAD)
1) L- Lawfulness, fairness and transparency 2) I - Integrity and confidentiality 3) P - Purpose limitation 4) S - Storage limitations 5) A - Accuracy 6) A - Accountability 7) D - Data minimisations