How long should you keep data for?
What type of data systems are used at Arcadis?
What is a project extranet system?
A computer network that allows external parties to view project files on a secure platform.
What are the benefits of cloud based storage systems?
Easy access anywhere in the world
Secure
Low set up cost
Teams can work in real time
Easy to control access
What is the Data Protection Act 2018?
It controls how all personal information is used by organisations, businesses or the government.
It is the UK’s version of the General Data Proectection Regulation (GDPR)
What is GDPR?
A regulation in EU law on data protection and privacy in the European Union and the European Economic Area. It also addresses the transfer of personal data outside the EU and EEA areas.
What is the purpose of GDPR?
Designed to harmonise data protection laws across all member countries as well as providing greater protection and rights to individuals.
It altered how businesses and other organisations handle the information of those that interact with them. There’s the potential for large fines and reputational damage for those found in breach of the rules.
Who are the key persons outlines within GDPR?
Data Controller - person who decides how and why to collect and use the data. Must ensure the processing of data complies with data protection law
Data Processor - a separate person who processes data on behalf of the controller
Data Subject - individual whom the personal data is about
Data Protection Officer - guarantor of compliance with the data protection regulations, without replacing the functions carried out by other supervisory authorities
What constitues as personal data?
Any information relating to a person or ‘Data Subject’ that can be used to identify a person directly or indirectly. This could be a name, photo, email address, bank details, posts on social media, medical information, or a computer IP address
The legislation not only applies to electronic data but to any records that are stored in a form that is easily searchable
What is the difference between a data processor and data controller?
A controller is the entity that determines the purposes, conditions and means of processing of personal data, while the processor is an entity which processes personal data on behalf of the controller
What are the key principals of GDPR?
What are the individual rights under GDPR?
Be informed
Access
Rectification
Erasure
Restrict processing
Data portability
To object
Automated decision making and profiling
Who enforces GDPR?
The Information Commissioners’s Office (ICO)
What is the Freedom of Information Act 2000?
Provides public access to information held by public authorities.
Public authorities are obliged to publish certain information about their activities
Members of the public are entitled to request information from public authorities (If requested the public body has 20 days to provide the information)
What is the maximum penalty for a breach of GDPR?
£17.5 million or 4% of a companies turnover which ever figure is higher, enforced by ICO
If you intend to destroy a document, what things should you consider beforehand?
What measures could be used to protect commercially sensitive information or if there was a conflict of interest?
Have a non-disclosure agreement in place
Physical separation of staff
Security of stored documentation, including locked filing cabinets and password protected servers
Consider online server access permissions
What ways can data be protected when transferring it on a client’s behalf?
What is an information barrier?
A physical and/or electronic separation of individuals within the same firm. The aim is to protect confidential information
What are the types of data?
Qualitative (hard data)- non-numerical data like interviews and observations
Quantitative (soft data) - numerical data and statistical analysis
Hard - physical copy, e.g. print out
Soft - on the internet not published,
What should you do if there is a data breach?
As well as report this to your organisations IT department to understand the route cause. It should be reported to the Information Commissioners Office (ICO) within 72 hours