Summary Of Experience Data Managment Flashcards
How would you ensure that data held on your property management system was fully accurate?
Input the information directly from the source ie lease and have a secondary surveyor review
What rights does the data protection act give?
- what is their data being used for.
- right to request data holds on them.
- request to delete information on an individual
When should a firm delete personal data?
As soon as it is no longer required
(No longer than 7 years to keep data)
How do you protect the data safe on your systems?
- password protect
- data encryption
- firewalls
- data cloud backup
What is the ICO and their role?
Information commission office
Promoting good practice in handling personal data and giving advice and guidance on data protection
Difference between tramps and horizon?
Tramps is internal universal system
Horizon is client system
Difference between gdpr and data protection act 2018?
GDPR is EU
Data protection supplements GDPR but post brexit is tailored to UK legislation and issues
Principles of GDPR
- lawfulness, fairness, transparency
- purpose limitation
- data minimisation
- accuracy
- storage limitation
- integrity and confidentiality
- accountability
What do you do if you believe a data breach has taken place?
- Contain the breach - isolate the system
- Access the severity of beach
- Notify the data protection officer internally and ICO needs to be notified within 72 hours
- Take stricter measures to prevent this in future
How you ensure data held on system was fully accurate?
In put directly, checked by a second surveyor.
Accountants can override as they have role based access control if error occurred
How can you protect your clients data?
- role based access controls (junior surveyors shouldn’t be able to tamper with clients data)
- password protection (3 phase access qube)
- firms have firewalls
- firm have secondary data base and cloud storage (sharepoint)
- data minimisation (only share amount required and delete when no longer needed)
- data protection plan going forward
How should data be collected?
- ethically, legally and responsibly
- make sure it complies with GDPR
(Think of principles)
Glory park example, you provided footage of CCTV.
What did you have to take into account?
- Tenant had to fill in “subject access form”
- As there was legitimate interest under GDPR, this was viable for them to view
- CCTV was also sent to police
Hemel Hempstead example. How did you store the info regarding the reinstatement clause?
Rights under GDPR?
the right to be informed;
the right of access;
the right to rectification;
the right to erasure or restrict processing; and
the right not to be subject to automated decision-making.