Data Management Flashcards

(17 cards)

1
Q
A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What Legislation are you aware of regarding Data Management?

A

Data protection Act 2018
Freedom of Information Act 2000
GDPR - 2018 (sits alongside the Data protection act)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Q. What is ISO 9001?

A

Internationally recognised standard for quality management systems, published by the International organisation for standardisation.

Provides a framework that organisations can follow to ensure they meet requirements of both customers and regulations
- Customer focus
- Leadership
- Engagement
- Process Approach

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Q. What is Information management?

A

Relates to how information is processed, collected, stored and organised.

Information is the outcome of all the data that is collected and stored.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Q. What quality management systems are you aware of?

A

ISO 9001 - most widely used globally

AS 9100 – For aerospace and defence sectors

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Q. What are the key documents in ISO9001?

A

Mandatory documents (scope of the quality management system

Mandatory records (minoring and measurement results, internal audit results etc)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Q. What is the Data Protection Act? Where does it cover?

A

Controls how personal information is used by organisations business or the government.

Obligatory compliance by any party who is using personal data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Q. Can you list the Key Persons outlined in the Data Protection Act?

A

Data subject – the person whose data it is
Data Controller - Decides how data is collected
Data Processor – Processes data on behalf of the controller
Data Protection officer – Oversee the data protection strategy
Information Commissioner – issues fines and checks compliance John Edwards in the UK.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Q. How does a company need to comply with the data protection act?

A

Only keep information needed
Don’t pass on sensitive personal data
Keep information held secure
Keep information for no longer than necessary

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Q. Can you list the 7 Principles outlined under the Data Protection Act?

A
  1. Lawfulness, fairness and transparency
  2. Purpose limitation
  3. Data Minimisation
  4. Accuracy
  5. Storage limitation
  6. Integrity and confidentiality
  7. Accountability
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Q. What Rights (8) are outlined under the Data Protection Act?

A

Right to be informed
Right to access
Right to rectification
Right to erasure
Right to restrict processing
Right to data portability
Right to object
Rights in Relation to Automated Decision-Making and Profiling

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Q. What is the GDPR? Where does it cover?

A

The General Data Protection Regulation (GDPR) is a comprehensive data privacy law that establishes a framework for the collection, processing, storage, and transfer of personal data.

Gives individuals the right to access and correct their personal data

Incorporated into UK law to sit alongside the Data Protection Act.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Q. What does UK GDPR cover / protect?

A

The information / data of people in the UK who’s information may be used by companies outside of the UK.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Q. What are the penalties for GDPR breach?

A

Minor infringements 10 million euros or 2% of turnover – (I.E Admin error)

Breach of principles - Major – 20 million euros or 4% of turnover (Unlawful processing of data, or failure to protect)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What are the other duties under the GDPR?

A

Report data breaches to the local authorities within 72 hours

Only obtain personal data with consent and a privacy note to explain.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Q. What is the freedom of information act (2005)?

A

Provides public right to access information held by local authorities

17
Q

Q. How long should information be held for?

A

Minimum requirements by the RICS are that they should be held in line with the lability period (6 years underhand or 12 years as a deed)

Although the best practice would be to hold it in line with the statue of limitations period which is 15 years.