Data protection Act 2018 (GDPR) Flashcards

1
Q

what personal data could I collect?

A
  1. employees.
  2. clients.
  3. prospective clients.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

what should you consider?

A
  1. Think about whether the information you hold is personal information?
  2. Document the purposes for which you are allowed to hold the information.
    3.Keep a record of consent (where needed) for processing, storage and retention.
    4.Seek permission to pass on details of any information related to the work (ie someones email/ telephone number)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

How can a Data breach occur?

A
  • employee mistake
  • hacking
  • cyber attacks
  • malware
  • loss of equipment
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

How to prevent data breaches?

A
  • Setting up proper passwords
  • use encryption for data transfer (this is part of MS 365) .
  • comply with data protection policy
    etc
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Data retention

A
  1. Only keep data for as long as necessary.
  2. May need to hold onto data in case of claims made against them.
  3. The limitation period may determine this, such as;
    - 6 years from service or 6 yrs from the loss. signed under hand.
    - A long stop position of 15 years, if they did not know they suffered a loss.
    - 12 years, if signed under seal
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Confidentiality agreements/non-disclosure agreements

A

As a RICS firm I will need to hold onto confidential information.
Often contractually responsible for protecting information that another party discloses to me.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Data retention contin..

A

Documents that were provided by your client or that your client has paid for belong to them, BUT your internal notes, emails and copy correspondence may not. However, remember that the client may also have a right to access the personal data you hold about them in those documents. If you are unsure about what should be provided, you may need to take legal advice.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is GDPR ?

A
  • Stands for: general data protection regulations.
  • it governs how your data is handled.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Who would usually own the copyright of a valuation report?

A

The surveyor, the client is licensed to copy it in connection with the purpose

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Could a Professional Indemnity Claim be based on lost or corrupted data?

A

Yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly