PE Data Management Flashcards

1
Q

How can you ensure data security?

A
  1. Firewalls
  2. Password management (30 days)
  3. Don’t leave devices unattended
  4. Departmental drives
  5. Encryption
  6. Virus protection (even on mobile devices)
  7. Suspicious emails
  8. Sensitive browsing should be done on a device and network you trust
  9. Caution about social media sharing
  10. Back up data
  11. Monitor financial accounts
  12. Automatic updates
  13. Two-step verification
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is ransomware?

A

Malware that encrypts and threatens to destroy, remove access to, or publicly post data unless a victim makes payment, which often increases as time elapses

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is another name for CEO fraud?

A

Phishing
Whaling

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is phishing/whaling/CEO fraud?

A

A malicious attempt to acquire sensitive information by masquerading as a trustworthy source via email, text or pop-up message, or to coerce an employee into making a money transfer

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What % of data breaches is it estimated that a company’s own employees may account for?

A

50%

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is EDM?

A

Electronic Document Management

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What does EDM do?

A

Collection of technologies that work together to provide a comprehensive solution for managing electronic assets

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Copyright?

A

Author of original work has exclusive rights to control distribution of work

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Can copyright be licensed, assigned or transferred?

A

Yes - it is an intellectual property right

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Who would usually own the copyright of a valuation report?

A

The surveyor, the client is licensed to copy it in connection with the purpose

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What key legislation relates to data protection in the UK?

A

Data Protection Act 2018

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What does GDPR stand for?

A

General Data Protection Regulation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is the purpose of GDPR?

A

Provide data protection rights to individuals and harmonise data privacy laws across Europe

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Does the Data Protection Act 2018 build upon the DPA 1988 principles?

A

Yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What does the DPA 2018 apply to?

A

Data controllers and processors

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is the definition of a data controller?

A

Entity that decides the purpose and manner that personal data is used, or will be used

17
Q

Do you need to comply with GDPR and the DPA 2018 as a surveyor?

A

Yes - most UK property firms process personal client data

18
Q

Can someone ask you to tell them what personal data you hold about them?

A

Yes

19
Q

Could a Professional Indemnity Claim be based on lost or corrupted data?

A

Yes

20
Q

Should you delete data when you no longer require it?

A

Yes

21
Q

What data is affected by GDPR and the DPA 2018?

A
  1. Personal data, including personal data and identifiers such as IP address
  2. Sensitive personal data, including genetic and biometric data
  3. Electronic data
  4. Manual data, e.g. business cards and written records
22
Q

What are the personal data principles of GDPR and the DPA 2018?

A

Processed lawfully, fairly and in a transparent manner

Adequate, relevant and limited to what is necessary in relation to the purposes for which they are procesed

Processed in a manner that ensures appropriate security of the personal data

Collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes

Kept in a form which permits identification of data subjects for no longer than is necessary

23
Q

What individual rights exist? (GDPR and DPA 2018)

A

Right to be informed
Right of access
Right to rectification
Right to erasure
Right to restrict processing
Right to data portability
Right to object
Rights in relation to automated decision making and profiling

24
Q

How long do you have to report a data breach to the ICO? (Information Commissioner’s Office)

A

Within 72 hours of awareness

25
Q

What does the Data Protection Bill 2017 do?

A

Amend GDPR in the UK, relating to academic research, financial services and child protection

26
Q

What do the Privacy and Electronic Communication Regulations 2003 (amended 2016) relate to?

A

Extra data protection rules for e-communicators e.g. consent for marketing emails and texts

27
Q

What legislation specifically relates to data held by public bodies?

A

Freedom of Information Act 2000

28
Q

How must a request be made by a member of public under the Freedom of Information Act 2000?

A

In writing

29
Q

How long does the public body have to respond to a Freedom of Information Act 2000 request?

A

20 days

30
Q

Does the public body have to respond to a Freedom of Infromation Act request 2000?

A

Yes - either within the information (plus a charge for processing) or refusal (with an explanation)

31
Q

Are there any exemptions under the FOI Act 2000?

A

Yes - too expensive to provide, unreasonable, not in the public interest

32
Q

What legislation relates to the disposal of old files?

A

Limitation Act 1980

33
Q

How long do you need to keep old files for?

A

At least 6 years, 12 if a deed (ideally 15 for PII reasons)

34
Q

What is an AVM?

A

Automated Valuation Model

35
Q

What does an AVM do?

A

Combine mathematical modelling and a database to provide property valuations