What legislation can you name that applies to data protection in the UK?
What does data protection mean and what does involve?
What is personal data?
Why do we have laws to protect our data?
Data protection laws aim to ensure all our personal data is kept securely, and used fairly, openly and legally.
Under data protection, what rights are reserved to individual?
What is UK GDPR? and what’s its purpose?
It’s the UK data protection framework which is based on Data Protection Act 2018 and UK GDPR; It’s a privacy and security law designed to protect personal data and how is this used by organisations, businesses and government
Is UK GDPR same as EU GDPR? When does the EU GDPR applies?
UK GDPR follows the same principles, rights and obligations as EU GDPR; The EU GDPR applies if UK organisations offer goods or services to individuals in the European Economic Area (EEA)
What are the Data Protection principles?
What is required under article 5(2) of GDPR?
The controller shall be responsible for, and be able to demonstrate compliance with the principles
Under the Data Protection Act, what are the key requirements for businesses handling data?
What are the consequences of non-compliance with data protection?
What are the financial penalties for data breach and how are they assessed?
Penalties for data breaches are assessed on a case-by-case basis (two tiers):
What are the key roles in the data management context?
**(If you are an employee and your organisation is the data controller, you might process data to fulfil your organisation’s role as a controller. This does not make you a data processor as defined in the legislation)
What is a data controller?
A data controller decides how and why personal data is processed and is directly responsible for GDPR
What is a data processor?
An organisation or individual that only processes personal data on behalf of the data controller, and in line with their instructions.
Can you give me some example of the data you manage ?
How do you ensure the data that you hold on your clients is kept secure and confidential?
What does the RICS say about confidentiality?
The RICS bye-laws say that client’s confidentiality must be maintained for all client’s affairs. This includes all historic information and info provide before an instruction.
Can information regarding client’s be accessed by a third party?
No, unless it’s been approved by the client
Which instances would you be able to disclose client’s information without their explicit consent?
Only when there is a statutory right overriding the client’s confidentiality, such as a request from the police or HMRC
If you receive an email sent by error from a competitor, containing confidential info, what would you do?
Firstly, the info contained in the email cannot be used for my own purpose, and I must advise the sender of this leakage and dispose of the email securely
What BCIS stand for? and what includes?
The Building Cost information Service provides cost and price data for the UK construction industry. It is a part of the Royal Institution of Chartered Surveyors.
Offers numerous product datasets such as
- Build Costs rates based on the location
- BCIS Schedule of Rates
- BCIS Dilapidations Estimating Price Set
How have you changed the way you managed data during COVID 19 and home working ?
What are the PII requirement for company data?
It is a requirement of our PII insurance that all contracts under deed are kept for a minimum of 12 years and to hand for 6 years. I am aware of the limitation act to claims which can be brought about up to 15 years after the act of negligence.