Data Management L1/L2 Flashcards

1
Q

Name the two main regulations/Acts relating to Data Protection

A

EU’s General Data Protection Regulations (now UK since Brexit)

Data Protection Act 2018

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

How has GDPR regulations changed since we have left the EU

A

UK has created own UK GDPR which mirrors the EU version

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Describe the purpose of the Data Protection Act 2018

A

The Act is a complete data protection system so covers personal data as outlined by the GDPR, it covers all aspects of general data covered under the Data Protection Act, 1998. Controls how personal information is used by organisations, businesses and government

Set the guidelines for companies for the collection, processing, storage and protection of personal data and to give individuals the rights to access, and correct their personal data and prevent it from being used for marketing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What Act does the DPA 2018 replace

A

DPA 1998

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Describe data breaches under Data Protection Act 2018

A

upto 4% of global turnover or 17.5 million euros

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What requirements are there for data breaches

A

• Data security breaches to be reported to the Information Commissioners Office (ICO) within 72 hours where there is a loss of personal data
CJ policy is to immediately speak to Joanne Dick, notify ICO within 72 hours

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Describe the purpose of a data protection officer

A

DPO is a role required by the ICO for overseeing a company’s data protection strategy and its implementation to comply with GDPR requirements

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Describe the role of a data controller

A

• A data controller decides how personal data is processed and responsible for GDPR

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Describe personal data examples

A

names, addresses, date of birth, CVs, appraisals, emails, texts

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

How is your organisation compliant with GDPR

A
  • Lock computers when not at desk
  • All paper documentation is filed in locked cabinets
  • When onsite, prevent taking personal information on paperwork
  • Prevent sharing passwords
  • Don’t have paper files unless really necessary
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Describe and define the 8 individual rights under GDPR

A
  1. Right to be informed - Individuals have the right to be informed about the collection and use of their personal data.
  2. Right of access and recieve copy of their personal data - Subject access request
  3. Right to rectification - incorrect personal data rectified
  4. Right to erasure - personal data to be erased
  5. Right to restrict processing
  6. Right to data portability
  7. Right to object to data processing
  8. Rights to automated decision making and profiling.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Describe the Freedom of Information Act 2000

A
  • Gives individuals the rights to access information held by public bodies.
  • Public bodies (government / Local authorities) are required to issue information held on individuals within 20 days of request.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Why is data management important in your area of practice

A

Fee pricing, tendering success, report writing, legal implications, research of comparable evidence

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Where do you get information / data in your area of practise

A

Google Maps, CoStar, EIG, Right Move Plus, Pricing books, Land Registry, Companies House

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What systems are there to manage information in your area of

A

Excel, Outlook, DMS, SharePoints, Connect (secure database for storing clients contact details)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Name data breaches

A

personal data sent to wrong participant, equipment containing data being stolen / information disposed of improperly

17
Q

How does CJ ensure confidentiality

A

good security of electronic data (firewalls, encryption and passwords), Non Disclosure Agreements

18
Q

What is an NDA

A
  • Non disclosure Agreements are a legal contract. It sets out how you share information or ideas in confidence. They commonly last 3-5 years and ensures information is kept confidential. `
19
Q

Name the 6 principles relating to the storage of personal data - UK GDPR

A
  1. Lawful and transparent processing
    • Personal data must be processed fairly, lawfully and in a transparent manner
  2. Legitimate purpose
    • Personal data should be obtained for specified, explicit and legitimate purposes
  3. Relevant and specific
    • Personal data should be adequate, relevant and limited to what is necessary in relation to the purpose for which it is processed
  4. Accurate
    • Personal data should be accurate and kept up-to-date
  5. Limited storage
    • Retain for no longer than is necessary for the purpose it is required
  6. Secure
    • Personal data must be protected against unauthorised access, unlawful processing, accidental loss, destruction or damage
20
Q

Name new RICS guidance on data

A

Data Handling and Prevention of Cyber Crime - in consultation
- cover data breaches, storing data etc alongside GDPR etc