Are you aware of any RICS guidance on AI
Yes, the RICS have recently published a new guidance note on AI which will be effective from March 2026
What does the UK GDPR state about the processing and collection of data from individuals
Individuals have the right to be informed. You must provide them with privacy information at the time you obtain their data
How do you keep personal data secure
Who is responsible for DPA/GDPR compliance within a business
Data Protection Officer (DPO)
What are the principles of UK GDPR
There are SEVEN:
(1) Lawfulness, fairness and transparency
(2) Integrity and confidentiality (security)
(3) Accuracy
(4) Data minimization – only collect it when you need.
(5) Purpose Limitation – be specific about the purpose of the data collection
(6) Accountability – record and prove compliance
(7) Storage Limitations – store data for a necessary limited period and then erase
What are the requirements under UK GDPR for data storage limitation and data minimisation
Data storage - data must be kept in a form that permits identification of data subjects for no longer than is necessary for the purposes for which the data is processed
Data minimisation - data must be accurate, relevant and limited to only what is necessary
What are the penalties for non-compliance with GDPR
Can be up to the greater of: 4% of the global turnover at the company; or £17.5m
What are the punishments for breaking an NDA
Civil - the party that was harmed by the breach can take legal action to enforce the agreement and seek damages for losses incurred
What are the 8 individual rights under UK GDPR
Explain the key principles of the Data Protection Act 2018
What is a SAR
Subject Access Request. Demand that the individual be given all the information that a company holds on them.
How long does Christie & Co store data
For a minimum of 6 years, we store hard data for 8 years and electronic data in perpetuity although are considering reducing this to 15 years.
This is because negligence claims can be brought against the company 6 years after a loss is suffered which can be over 10yrs from the date of valuation. I note that the Limitation Act 1980 has a long-stop limit of 15 years from the date of the negligent act or omission.
What are the responsibilities of data users under the legislation
Give an example how Christie and Co are compliant with UK GDPR and the Data Protection Act
L3 - Take me through the new process
A new ready made group valuation template in excel that is automated in terms of summarising the valuation and consolidating the individual property accounts
What is GDPR
General Data Protection Regulation: Comprehensive data protection law that covers the collection, processing and storage of data. First introduced in the EU in 2018
What is secondary data
Data that is collected from a third party source
How do you ensure that data is collected accurately
Use clear and structured forms, verify data at the point of entry, regular reviews and data audits
What are NDAs and why are they used
Non Disclosure Agreement - a legally enforceable contract between two parties relating to sensitive information
Why is it important to test data processes
To ensure the accuaracy of the data
What are the limitations of secondary data
We can not verify the accuaracy of the data as we did not collect it ourselves
What is personal data
Data that from which an individual could be personally identfiable from (e.g Name, DoB, Etc)
Comparable collection
L2 - What types of transactions were you looking for
Freehold and Leasehold pharmacy and dental transactions
L2 - How do you prevent being sent personal infomation from Clients?
Within my requesting infomation email when undertaking a valuation where I will be required to analyse staffing schedules, I stress the importance of removing the Personal Infomation (staff names) and put the text in RED to stress the importance