Data Mangement Flashcards
(56 cards)
Why is it important to consider data sources?
To consider the reliability and associated risks
Where possible should verify data against alternative sources through ‘triangulation’
Why is it important data is stored safely?
To keep safe from corruption and control access to ensure privacy and protection
In order to comply with UK GDPR, as well as the RICS RoC and bylaws of confidentiality
What data security technologies are there?
Disk Encryption - on a secure hard disk drive
Regular backups off site
Cloud storage
Password protection and anti-virus software protection
Firewalls and disaster recovery procedures
What data security actions are undertaken in your office?
Password protection
firewalls
disaster recovery
Cloud storage
What is Copyright?
A set of exclusive rights granted to the author or creator of any original work
Rights can be licensed, assigned or transferred
What is intellectual property?
intangible property that is the result of creativity, such as patents, copyrights, etc
What is Crown Copyright?
Refers to all material created and prepared by the government eg. laws, public records, official press releases and OS Mapping
Should you acknowledge copyright in your work?
Yes for any copyright information duplicated in your work
What is set out in the UK General Data Protection Regulation and the Data Protection Act, 2018?
Additional supplement to UK GDPR (2016) - EU no longer applies
Aims to create a single data protection regime affecting businesses and empower individuals to take control of how their data is used by third parties
What are the 7 principles of GDPR?
- Data minimisation
- Purpose limitation
- Storage limitation
- processed fairly & lawfully
- Accurate & up to date
- Security
- confidentiality
What are the key requirements included in the Data Protection Act 2018?
An obligation to conduct data protection impact assessment for high risk holding of data
Gives people rights to be informed about how their personal information is used
What is a data controller?
the person directly responsible for ensuring GDPR, decides how and why personal data is processed
What is the principle of ‘data accountability’?
ensuring that organisations can prove to the information commissioner’s Office (ICO) how they comply with the regulations
What should you do if there is a data security breach?
Must be reported within 72 hours to ICO where there is a loss of personal data and risk of harm to individuals
What are the penalties for non compliance with UKGDPR?
fines of up to 4% of global turnover of the company or £17.5million (whichever is greater)
What are the principles of the UK GDPR?
Article 5(1) principles relating to storage of personal data
Article 5(2) requires that the ‘controller shall be responsible for compliance with the principles
How does Article 5(1) of the UK GDPR state data should be stored?
- Lawfully, fairly and in a transparent manner
- Collected for specified, explicit and legitimate purposes
- Adequate, relevant and limited to what is necessary for purpose
- Kept in form which permits identification of data subjects
- Appropriate level of security
What are the 8 individual rights under UK GDPR?
Rectification
Erasure
Access
Data portability
Restrict processing
Automate decision making
Informed
Object
What is the Freedom of Information Act 2000?
Gives individuals the right of access to information held by public bodies
The public body must declare whether it holds info
Public body has 20 days to supply info requested
It can charge for the provision of info
What are the exemptions to the freedom of information act 2000?
- If contrary to GDPR Requirements
- It would prejudice a criminal investigation or a person/organisations personal interest
How can Security of data be improved?
Firewalls
Encryption
Cloud-based systems
Passwords
What is a non-disclosure agreement?
A legally enforceable contract between 2 parties relating to sensitive information
Creates a confidential relationship
What RICS Professional Standard has been proposed?
A standard on Data Handling and Prevention of Cybercrime - covering best practice and mandatory obligations for the capture, storage and sharing of data
What happens if an NDA is breached?
The party that was harmed can take legal action to enforce the agreement and seek damages for any losses that were incurred