Data Management Flashcards

(41 cards)

1
Q

What does GDPR stand for ?

A

General Data Protection Regulation (how we collect and process personal data)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

When did GDPR come into affect ?

A

25 May 2018 (UK).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are the maximum fines (UK GDPR) , how are the fines calculated?

A

• £17.5 million or 4% of the total annual worldwide turnover in the preceding financial year, whichever is higher

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Have you completed any training on GDPR ? what did you learn ?

A

Yes, please see CPD.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What legislation covers data protection in the UK ?

A

Data Protection Act 2018 and UK GDPR

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Who does Freedom of Information Act Apply to?

A

Public right of access to information held by public authorities.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Does GDPR apply post Brexit ?

A

Converted into UK Law on 1st Jan 2021 under the title UK GDPR.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What will the changes include (GDPR post Brexit)?

A

UK government will control the UK GDPR as opposed to the European union.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Who oversee information rights in the UK ?

A

ICO - Information Commissioners Office

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What happens if you are sharing or processing data from the EU ?

A

Adhere to :
• UK GDPR
• EU GDPR
• Data Protection Act 2018

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Who enforces the data protection ?

A

Information commissioners office - ICO

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

How do you ensure data you hold on clients is kept secure and confidential ?

A

1) Smart passwords/Firewalls/Anti-virus software.
2) Limit access to sensitive data.
3) Update security

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What are the 7 GDPR principles? - LADSPAS

A
  • Lawfulness, fairness and transparency – leave the individual fully informed
  • Accuracy – where necessary kept up to date, erase inaccurate personal data without delay
  • Data minimisation – collect the minimum data you need
  • Storage limitation – Retain the data for a necessary limited period and then eras
  • Purpose limitation – must inform your clients about the purpose of the data collection
  • Accountability – Record and prove compliance
  • Security - Integrity and confidentiality – Keep it secure, locked filing cabinet or fire wall
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

How have you changed the way you managed data during COVID 19 and home working ?

A

1) Only use work equipment
2) The storage of files/documents to be locked away,
3) Regular update on password protected equipment etc.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Why do you keep company data for 12 years?

A

PII insurance requirement (contracts under deed are kept for a minimum of 12 years and under hand for 6 years).

I am aware of the limitation act to claims which can be brought about up to 15 years after the act of negligence.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is project extranet?

A

Network that allows controlled access from the outside for specific project purposes.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

What is BIM?

A

Building Information Modelling. Software creating 3D models that allow industry professionals to better plan, design, construct and mange buildings/infrastructure.

18
Q

What are the disadvantages of BIM?

A

Very expensive

Lack of use = less experts

19
Q

How does BIM effect your role as a CA?

A

I’ve not used it but I would imagine that it simplifies the process by theoretically reducing the amount of variations required.

20
Q

What should you do if there is a data breach ?

A

Inform the Information Commissioner’s Office… no later than 72 hours after becoming aware of it.

21
Q

What are ISO Standards ?

A

International Organisation for Standardisation.
An international standard setting body of representatives from varying national standards.
• ISO 9000 – Quality Management Systems
• ISO 8000 – Data Quality

22
Q

What is the limitations act ?

A

The Limitation Act 1980 is an Act of the Parliament applicable only to England and Wales. It is a statute of limitations which provides timescales within which action may be taken for breaches of the law.

23
Q

What year was the Limitation Act published?

24
Q

Can you give me some example of the data you manage ?

A
  • Client details
  • Contact details
  • Project details
  • Complaints
25
What is personal data ?
Personal data only includes information relating to natural persons who: • can be identified or who are identifiable, directly from the information in question; or • who can be indirectly identified from that information in combination with other information.
26
What are a persons right under the Data Protection GDPR rights ?
* The right to be informed * The right of access * The right to rectification * The right to erasure * The right to restrict processing * The right to data portability * The right to object * Rights in relation to automated decision making and profiling
27
What is the process if there is a data breach ?
Duty on all organisation's to report certain personal data breaches to the relevant supervisory authority (72 hours). • If high risk of adversely affecting individuals’ rights and freedoms, you must also inform those individuals without undue delay. • Robust breach detection, investigation and internal reporting procedures in place. • Keep a record of any personal data breaches (regardless of notification).
28
Can you expand on what BCIS is ?
The Building Cost Information Service: •cost and price data for the UK construction industry.
29
What are the principles of the Data Protection Act 2018 ?
``` LADSPAI • Lawfulness, fairness, and transparency. • Accuracy. • Data minimization. • Storage limitation. • Purpose limitation. • Accountability. • Integrity and confidentiality. ```
30
What is the Data Protection Act 2018 ?
Controls how your personal information is used (organisations, businesses or the government).
31
What are the principles of the data protection act ? PCRCDM
* Proportionality * Commitment (Top Level) * Risk assessment * Communication * Due Diligence * Monitor and Review
32
Why is it important that we safeguard information?
Can be used maliciously.
33
What kind of information is 'sensitive' information?
Health records, Financial information Address
34
What are the benefits of using external data sources such as BCIS etc?
* Industry wide data * Standardisation * Data management
35
What does your company do to ensure a clients information is kept secure and confidential ?
* Operate a clear desk policy * Shredding of details etc * Two factor authentication of IT systems
36
How long do you keep client’s data and how do you ensure it is deleted when necessary?
Dependent on the type of data and the contract • Under hand - 6 years • Under deed - 12 years • Limitations act – 15 years
37
What types of breaches are there under GDPR ? DDA
* Disclosure * Destruction * Alteration
38
What is personal information ?
* Address * DOB * Bank details
39
What is sensitive information/data ?
* Medical records | * Sexual orientation
40
Why does using standard templates such as CAD and Reports assist your company?
Flexibility, Easy to update (centrally), Provide consistency = professional Easily tracked and updated.
41
Who are the key persons outlined within GDPR?
1) CONTROLLER (determines purpose and means of processing personal data- EMPLOYER) 2) PROCESSOR- (Processes data on behalf of the controller- call centre) 3) Data Protection Officer (DPO)- Leadership role-overseeing data protection approach, strategy, implementation.