What is the maximum fine for a GDPR breach?
Tools at our disposal include assessment notices, warnings, reprimands, enforcement notices and penalty notices (administrative fines). For serious breaches of the data protection principles, we have the power to issue fines of up to £17.5 million or 4% of your annual worldwide turnover, whichever is higher.
What are subject access requests?
A request for disclosure of all (or some) of the personal data we hold of someone. Generally includes name, address, DOB, passport details, utility bill, credit card info.
Simple request from client for contact details we hold from them should not be counted as an SAR
SAR should be referred to DPO asap, 1 calendar month to respond.
What is CJ’s procedure for reporting and managing a data breach?
Loss must be reported immediately to line manager and either Head of IT or the DPO.
How do you manage data securely?
I use a document management system to store files and emails, I undertake regular training to ensure best practice. I always double check who an email is addressed to before sending.
What is your understanding of GDPR?
General Data Protection Regulation - toughest privacy and security laws in the world
What Act applies to data protection?
The Data Protection Act 2018
What types of data are there?
Personal, sensitive personal information and privileged information
What rights to individuals have in relation to data protection?
What is EDM?
Electronic Document Management
Who would usually own the copyright of a valuation report?
The surveyor, the client is licensed to copy it in connection with the purpose
Who does the Data Protection Act 2018 apply to?
Data controllers and processors
Could a PI claim be based on lost or corrupted data?
Yes