Data Management Flashcards

(20 cards)

1
Q

What does the Data Protection Act 2018 control?

A

How personal data is used by organisations and businesses

It protects personal data and requires adherence to seven data protection principles.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

List the seven data protection principles (SAIL PAD).

A
  • Storage limitation
  • Accuracy
  • Integrity and confidentiality
  • Lawfulness, fairness and transparency
  • Purpose limitation
  • Accountability
  • Data minimisation

These principles guide the handling of personal data under the Data Protection Act.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are the personal rights under GDPR (BARE CORD)?

A
  • Be informed
  • Access
  • Rectify
  • Erasure
  • Object
  • Restrict processing
  • Data portability

These rights empower individuals regarding their personal data.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

True or false: The GDPR came into force in May 2018 as an EU regulation.

A

TRUE

It sets out broad principles for data protection across the EU.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What does the DPA 2018 do?

A

Supplements GDPR and incorporates it into UK law

It adds UK-specific provisions to the GDPR framework.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Under Section 170 of the Data Protection Act 2018, what is an offence?

A
  • Obtain or disclose personal data without consent
  • Procure disclosure of personal data without consent
  • Retain personal data without consent

These actions are considered serious violations of data protection laws.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Who is the Data Protection Officer responsible for VOA?

A

David Burke

The DPO oversees compliance with data protection regulations.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What are the mandatory requirements for firms according to the RICS Professional Statement?

A
  • Risk assessments for client data
  • Define and adhere to data retention policy
  • Appoint a person responsible for data handling
  • Use passwords to control access

These requirements aim to enhance data security and compliance.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

How can you keep data safe? List some methods.

A
  • Lockable secure document storage
  • Electronic information on encrypted servers
  • Lock computer when away from desk
  • Comply with employer’s IT policies
  • Obtain clients’ written permission to share data

These practices help ensure the security of personal data.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What does the CRCA stand for?

A

Commissioners for Revenue and Customs Act 2005

It applies to all HMRC officers and sets out statutory functions and confidentiality duties.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is required in case of a data breach?

A
  • Report internally within 48 hours
  • Notify ICO within 72 hours if necessary
  • Inform affected individuals if high risk

These steps are crucial for compliance and protecting individuals’ rights.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What does the Freedom of Information Act 2000 provide?

A
  • Right to request information from public authorities
  • Authority must respond within 20 days

It ensures transparency and accountability in public authorities.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is the maximum fine under GDPR?

A

£17.5 million or 4% of global turnover

This penalty applies to serious violations of data protection laws.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is a non-disclosure agreement (NDA)?

A

Protects against sharing confidential data

Clients typically request an NDA before sharing sensitive information.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is the purpose of the Data Use and Access Act 2025?

A

Allows ‘stop the clock’ for service access requests

It requires organisations to conduct reasonable and proportionate searches for Subject Access requests.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is a data controller under GDPR?

A

The organisation or individual that determines the purposes and means of processing personal data

Data controllers are responsible for ensuring compliance with data protection laws.

17
Q

What is a data processor under GDPR?

A

The organisation or individual that processes personal data on behalf of the controller

Data processors must follow the instructions of the data controller.

18
Q

List the principles of the ICO data sharing code of practice.

A
  • Accountable
  • Lawful
  • Fair
  • Secure

These principles guide responsible data sharing practices.

19
Q

What is the purpose of the RICS global standard on responsible use of AI?

A

Provide a basis for upskilling the profession

It includes provisions for clear policies around data and AI use.

20
Q

What must clients be informed about regarding AI use?

A

When AI has been used and given the option to opt out

This ensures transparency and client consent in AI applications.