DATA MANAGEMENT Flashcards

(32 cards)

1
Q

Are you aware of any RICS guidance on AI

A

Yes, the RICS have recently published a new guidance note on AI which will be effective from March 2026

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What does the UK GDPR state about the processing and collection of data from individuals

A

Individuals have the right to be informed. You must provide them with privacy information at the time you obtain their data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

How do you keep personal data secure

A
  • Authenticated access to systems
  • Two factor authentication
  • Encryption
  • Ensure integrity of data collection systems
  • Continually evolve and test systems
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Who is responsible for DPA/GDPR compliance within a business

A

Data Protection Officer (DPO)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are the principles of UK GDPR

A

There are SEVEN:
(1) Lawfulness, fairness and transparency
(2) Integrity and confidentiality (security)
(3) Accuracy
(4) Data minimization – only collect it when you need.
(5) Purpose Limitation – be specific about the purpose of the data collection
(6) Accountability – record and prove compliance
(7) Storage Limitations – store data for a necessary limited period and then erase

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What are the requirements under UK GDPR for data storage limitation and data minimisation

A

Data storage - data must be kept in a form that permits identification of data subjects for no longer than is necessary for the purposes for which the data is processed

Data minimisation - data must be accurate, relevant and limited to only what is necessary

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What are the penalties for non-compliance with GDPR

A

Can be up to the greater of: 4% of the global turnover at the company; or £17.5m

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What are the punishments for breaking an NDA

A

Civil - the party that was harmed by the breach can take legal action to enforce the agreement and seek damages for losses incurred

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What are the 8 individual rights under UK GDPR

A
  • Right to Access
  • Right to be informed
  • Right to Object
  • Right to Erasure
  • Right to Rectification
  • Right to restrict processing
  • Right to data portability
  • Right to automated decision making and profiling
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Explain the key principles of the Data Protection Act 2018

A
  • Processed lawfully, fairly and in a transparent manner
  • Collected for specified and legitimate purposes
  • Accurate
  • Not transferred to countries with less info than your own
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is a SAR

A

Subject Access Request. Demand that the individual be given all the information that a company holds on them.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

How long does Christie & Co store data

A

For a minimum of 6 years, we store hard data for 8 years and electronic data in perpetuity although are considering reducing this to 15 years.

This is because negligence claims can be brought against the company 6 years after a loss is suffered which can be over 10yrs from the date of valuation. I note that the Limitation Act 1980 has a long-stop limit of 15 years from the date of the negligent act or omission.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What are the responsibilities of data users under the legislation

A
  • To process data lawfully, fairly and in a transparent manner
  • To only collect data for a specified and legitimate purpose
  • To ensure data is Accurate
  • Not to transfer data to countries with less info than your own
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Give an example how Christie and Co are compliant with UK GDPR and the Data Protection Act

A
  • Fair Processing Notice on our website (Right to be Informed)
  • When distributing marketing emails there is a clearly identifiable unsubscribe option (Right to be Informed)
    -Privacy notice when we collect data
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

L3 - Take me through the new process

A

A new ready made group valuation template in excel that is automated in terms of summarising the valuation and consolidating the individual property accounts

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is GDPR

A

General Data Protection Regulation: Comprehensive data protection law that covers the collection, processing and storage of data. First introduced in the EU in 2018

17
Q

What is secondary data

A

Data that is collected from a third party source

18
Q

How do you ensure that data is collected accurately

A

Use clear and structured forms, verify data at the point of entry, regular reviews and data audits

19
Q

What are NDAs and why are they used

A

Non Disclosure Agreement - a legally enforceable contract between two parties relating to sensitive information

20
Q

Why is it important to test data processes

A

To ensure the accuaracy of the data

21
Q

What are the limitations of secondary data

A

We can not verify the accuaracy of the data as we did not collect it ourselves

22
Q

What is personal data

A

Data that from which an individual could be personally identfiable from (e.g Name, DoB, Etc)

23
Q

Comparable collection

L2 - What types of transactions were you looking for

A

Freehold and Leasehold pharmacy and dental transactions

24
Q

L2 - How do you prevent being sent personal infomation from Clients?

A

Within my requesting infomation email when undertaking a valuation where I will be required to analyse staffing schedules, I stress the importance of removing the Personal Infomation (staff names) and put the text in RED to stress the importance

25
L2 - How do you react when you are sent personal staffing infomation?
I make sure to delete it immedietly. I then contact the client to confirm I have deleted the personal infomation and then request that any personal infoamtion is redacted and resent in a new format.
26
When did UK GDPR come into effect
The original GDPR came into effect in the UK on May 25, 2018, alongside the Data Protection Act 2018. Following Brexit, the UK adopted its own version, the UK GDPR, which took effect on January 1, 2021, to replace the EU's GDPR for the UK.
27
You say you know the limitations of using secondary data, what are these?
Its **quality and accuracy are difficult to verify** because the collection methods are unknown. Other limitations include l**ack of control over the data's credibility**, potential for bias, and data that may be incomplete or incompatible
28
Why do you cross check data with Companies House and Land Registry?
Provides a comprehensive view of a company's ownership, assets, and financial health for robust due diligence, risk mitigation, and fraud prevention. Companies House records business information, while the Land Registry documents property ownership
29
What makes some financial data sensitive?
Financial data is sensitive because its exposure can lead to identity theft, fraud, and significant financial loss for both individuals and organizations - **IN THE WRONG HANDS**
30
You mention the importance of removing personal details from information. It is not necessarily bad to hold personal data, *what principle dictates your decision making regarding personal data?*
The UK's GDPR - **Data minimization:** Only the minimum amount of personal data necessary for the intended purpose is collected and stored.
31
What are the risks of holding unnecessary personal information?
Risks range from identity theft and personal danger to financial loss, reputational damage, and threats to national security.
32
What GDPR principle related to your decision to use an encrypted storage system?
Related to the principle of **Integrity and Confidentiality (security)**. Encryption is a key technical measure for protecting personal data and demonstrating compliance with this principle.