Data Management Flashcards
(26 cards)
What is the Commissioners for Revenue and Customs Act 2005 (CRCA)
It applies to all HMRC officers.
It expressly provides duty to keep information confidential.
Criminal penalties for wrongful disclosure
What is Section 17 of the Commisioners for Revenue and Customs Act 2005 (CRCA)?
Section 17- Allows sharing of information between HMRC and VOA (SDLT, RALDs)
What is Section 18 of the Commisioners for Revenue and Customs Act 2005 (CRCA)?
Section 18- Permits disclosure of information outside VOA/HMRC in line with our function (sharing RALDs with agents).
Must be proportionate and necessary.
What is Section 19 of the Commisioners for Revenue and Customs Act 2005 (CRCA)?
Section 19- makes it criminal offence to disclose information that can identify an individual, unless it’s covered by Section 18.
What are Sections 20 and 21 of the Commisioners for Revenue and Customs Act 2005 (CRCA)?
Sections 20 & 21- Covers when information can be disclosed where it is either in the public interest or it is to a prosecuting authority.
What are Sections 22 and 23 of the Commisioners for Revenue and Customs Act 2005 (CRCA)?
Sections 22 & 23- Relates to rights to information under GDPR and FOIA and set out how these requests should be treated.
What Act covers HMRC officers?
The Commisioners for Revenue and Customs Act 2005 (CRCA)?
What is the Freedom of Information Act (FOI) 2000?
Gives people the right to request information from public authorities.
What are the two rights under the Freedom of Information Act (FOI) 2000?
- To know if personal information is held.
- For that information to be communicated.
What are the statiatory deadlines for Freedom of Information requests?
20 days
What are the reasons for refusal of a FOI request?
- prejudice a criminal matter under investigation, or a person’s commercial interests.
- Too costly or too much staff time.
- The request is vexatious (difficult to deal with/cause anger).
- The request is a repeat request from same person.
- The request is contrary to GDPR
What are the VOA’s limitations to dealing with FOI requests?
Must not disclose property related information as it could identify an individual.
What is the Data Protection Act 2018?
UK’s GDPR.
Controls how personal data is used by organisations and businesses.
What are the 7 principles of GDPR?
LAMP ASS:
Lawfulness, fair and transparency.
Accuracy.
Minimisation of data.
Purpose limitation.
Accountability.
Storage limitation.
Security (integrity and confidentiality).
What are the 10 individual rights of GDPR?
RARE APC COI:
Rectification
Automation
Restriction
Erasure
Access
Portability
Consent
Complain
Object
Informed
What is the statutory deadline to report a breach under GDPR?
Must be reported internally within 72 hours of becoming aware.
Must be reported to Information Commisioner’s Office (ICO) if breach likely to risk people’s rights within 72 hours.
What must each public authority have to ensure GDPR?
A dedicated Data Protection Officer (DPO)
What is the maximum fine for a breach of GDPR?
20 million euros or 4% of global turnover.
What is copyright?
Set of exclusive rights granted to creator of work, is a form of intellectual property.
Essential to acknowledge any copyright for information duplicated in work.
What external data do you use for your work?
CoStar- property information such as lease and sales data.
Expedian GOAD- Occupier information
How do you protect any sensitive data in relation to inspections?
- Ensure all plans and measurements are kept confidential before, during, and after inspections.
- Ensure clear desk policy is maintained.
- Secure physical plans and data safely post-inspection.
- Save all plans and data securely digitally, in secure EDRM application.
If you discovered a data breach, how would you deal with it in your organisation?
- Security incidents should be reported on the Security Incident Reporting Tool within 48 hours.
- If the breach risks anybody’s personal data being breached, then the Information Commissioners Office (ICO) must be informed within 72 hours.
What is the defintion of personal data?
Any information relating to an individual or identifiable person.
What is a data breach?
Is a security incident where unauthorised individuals gain access to sensitive or confidential information.