Data Management Flashcards

1
Q

What are 8 Individual Rights under UK GDPR?

A
  1. Right to be informed
  2. Right to access
  3. Right to rectification
  4. Right to erasure
  5. Right to restrict processing
  6. Right to data portability
  7. Right to object
  8. Rights to automated decision making and profiling
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

How is data managed and protected by your firm?

A

Answer
- SharePoint acts as our secure document storage system
- Documents are backed up on our XDrive
- Confidential documents are stored securely
-Formatting is standardised across all documentation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is GDPR?

A

General Data Protection Regulations.

The EU’s GDPR no longer applies in the UK.

The UK’s GDPR is supplemented by the Data Protection Act 2018 - replacing the Data Protection Act 1998.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are the main principles of collecting personal data outlined in UK GDPR?

A

Answer:
1. lawfulness, fairness and transparency
2. Purpose limitation - what data is used for
3. Data minimisation -
4. Accuracy and kept up to date
5. Storage limitation - kept in form which permits identification of data subjects
6. Integrity and confidentiality
7. Accountability

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What things must a company do to ensure GDPR compliance?

A

Answer:
- Raise awareness across business
- Audit all personal data
- Update privacy notice
- Review procedures supporting individuals rights
- Review how you seek, obtain and record consent

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

How can you make sure data storage is secure?

A

Answer:
- Disk encryption - secure hard disk drive
- Regular backups off site
- Password protection and use on anti-virus services
- Firewalls and disaster recovery procedures

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

How do ensure data sources are reliable?

A

Answer:
- I should reverify data against an alternative source through ‘triangulation’

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is the ICO in GDPR?

A

The Information Commissioner’s Office (ICO) is the UK’s independent body set up to uphold information rights, covering laws including the Data Protection Act 2018, Freedom of Information and Privacy and Electronic Communications Regulations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

The difference between Data processor and Data controller?

A

The UK GDPR defines a processor as: ‘processor’ means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller. Processors act on behalf of the relevant controller and under their authority

What is a data controller for GDPR?
The data controller determines the purposes for which and the means by which personal data is processed. So, if your company/organisation decides ‘why’ and ‘how’ the personal data should be processed it is the data controller.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What personal data do you come into contact with?

A

For Inspections during lease extension purposes I come into contact with leaseholders mobile phone numbers and emails - I am always sure to delete any reference to leaseholders contact details following my inspections.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Under GDPR, if there was a data breach what would happen next and what would be your role?

A
  1. Work with my head operations in my company and determine if the breach has to be reported to the ICO
  2. By Law you have to report the personal breach to the ICO without undue delay and within 72 hours
  3. In your log, write down facts of what has happened
  4. Try and contain the breach
  5. Assess risk for customers
  6. Act to protect those affected
  7. Submit report
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What happens if you breach data protection UK?

A

The UK GDPR and DPA 2018 set a maximum fine of £17.5 million or 4% of annual company turnover – whichever is greater – for infringements

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What does the Freedom of Information Act 2000 do?

A

Gives individuals the right of access to information held by public bodies:

  • Public body has to confirm they have information requested
  • 20 days to supply information
  • Public body can charge for provision of
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is a non-disclosure agreement?

A

An NDA creates the legal framework to protect information from being stolen or shared with competitors or third parties.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What happens if a non-disclosure agreement is broken?

A

Violating an NDA leaves you open to lawsuits from your employer/client, and you could be required to pay financial damages and possibly associated legal costs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly