Data Management Flashcards

1
Q

Can you name three pieces of legislation relevant to data management?

A

UK General Data Protection Regulation (UK GDPR)

Data Protection Act 2018

Freedom of Information Act 2005

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are some data security technologies?

A

Two factor authentication

Passwords

Disk encryption

Regular off-site back ups

Virtual Private Network

Anti-virus software

Firewalls

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

When did the UK GDPR legislation change and what changed?

A

UK GDPR was almost entirely transcribed from the EU GDPR and is supplemented with the Data Protection Act 2018

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is a firewall?

A

It is a network security device that monitors traffic to and from your network and blocks anything that appears dangerous

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is a Virtual Private Network?

A

A mechanism for creating a secure network for computers and servers

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are some of the principles of UK GDPR?

A

Data must be processed lawfully, fairly and transparently

Data must be used for specified, explicit purposes

Used in a way that is relevant and limited to what’s necessary

Accurate and kept up to date

Data is retained for only as long as necessary

Handled in a way that is secure

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is personal data?

A

Any data that can be used to identify a natural person, so name, address, a photo an email address, bank details, social networking profiles, medical information

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What are individual rights under the UK GDPR/DPA

A

Right to be informed how data is used
Right to access personal data
Right to correct data
Right to have your data erased
Right to stop or restrict processing of your data
Right to data portability

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What happens if a breach occurs?

A

Must report to the Information Commissioners Office (ICO) within 72 hours if there is a risk to individuals

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What are the maximum penalties?

A

Up to 4% of global turnover, or £17.5m, whichever is greater.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is your understanding of the term Confidentiality?

A

Information shared with you is not to be shared with another party, unless they have been given permission too

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is the Freedom of Information Act 2000

A

The act permits the public right of access to information held by public authorities.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

If two separate departments within your firm were working for two
rival companies how would you ensure client sensitive data was
managed?

A

I would make the client aware of the risks involved and check their understanding of the conflict of interest.

Separate working locations from each of the teams would need to be put in place.

Secure document and data storage would be arranged to be used exclusively for the separate teams.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

How do you manage these sources of information to ensure
compliance with the legislation?

A

The electronic information is kept securely on encrypted servers

I am always sure to lock my computer when away from my desk

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

How is data kept securely on C&Cos in house database?

A

All data is stored on an encrypted server that has regular off site back ups. It can only be accessed by employees who are either plugged into the server or accessing it via a VPN.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Talk us through the process of data extraction and analysis for the UKH Benchmarking Report?

A

A survey goes out to all of UKH members, requesting financial and property information. This data is anonymised by UKH and then provided to us in raw format.

The raw data is then consolidated into different segments, such as casual dining, food-led pubs, hotels, wine bars, nightclubs and others, and then analysed to understand how this has changed over time.

16
Q

What conclusions did the data analysis help you make?

A

The trend of rising operating costs was unfortunately continuing. Interestingly, this was driven by rising utility costs and staffing costs were actually lower as staffing efficiencies from furlough were realised.

Accommodation-led businesses saw the greatest like-for-like revenue growth as the staycation trend helped regional room focussed businesses capitalise on demand.

17
Q

Did you have to sign an NDA for the disposal of the 60 properties?

A

Yes, a non-disclosure agreement was signed

18
Q

Why did you have to sign an NDA?

A

So that the confidential data being shared with us is prevented from being shared to other recipients

19
Q

Did the deal go ahead?

A

It is still ongoing so I cant share any information on the company or properties

20
Q

What is your understanding of Intellectual Property and Copyright?

A

This is the right to control the use and ownership of original works.

Work generally created by an employee usually belongs to their employer unless copyrights are put in place

21
Q

What are the benefits of cloud-based storage systems?

A

Cheaper
Backed up securely to encrypted servers
Environmentally friendly
Convenient
More efficient for working in teams

22
Q

What sources of data do you use on a daily basis?

A

Benchmarking data
Comparable evidence/transactional data
Business planning data - invoice forecasting, quote tracking
Financial data
Capital expenditure data

22
Q

Who are the key persons outlined within GDPR?

A

Data controller - person in charge of how data is processed (eg. employer is data controller of employees data)

Data processor - person that process data on behalf of a data controller

Data Protection Officer - responsible for overseeing data protection strategy

23
Q
A