What is UK GDPR covered by?
Data Protection Act 2018
What does GDPR stand for?
General Data Protection Regulation
What are the indivdiual rights under UK GDPR?
Right to access
Right to be informed
Right to object
Right to use for their own purposes
Right to erasure
Right to rectification
What are the principals of UK GDPR?
What is a non-disclosure agreement?
A contract that ensures confidential information isn’t disclosed to any third parties
Who issues NDAs?
In my last company, I had a legal team who issued them
Are they legally binding?
yes
Can anything in them be legally binidng? If so, what?
What security technologies are you familiar with?
Password protection
Cloud storage (save data and files on a remote, secure servers. Accessed via the internet/wifi connection. Access anywhere)
Encryption (processing info into coded format so it is unreadable)
What would you do if you became aware of a data breach?
Must be reported to Information Commissioner’s Office within 72 hours of becoming aware of them if there is risk of harm to people or loss of personal data
What are the penalties for breaching data under GDPR/DPA18?
£17.5 million of 4% of annual global turnover (whichever is highest)
What is the Freedom of Informtion Act 2000?
1) Gives people the right to access data held by public bodies
2) Must be issued within 20 working days
What is personal data?
Data that can expose the identity of an individual
How can security of data be improved/how do you ensure data is stored safely?
Firewalls, encryption, passwords, cloud storage
What is the Data Protection Act 2018?
UK’s implementation of GDPR
Governs how personal data is used by companies and the government
When can data be shared under UK GDPR guidelines?
Only share if I have consent or if there is a lawful reason
Ensure secure transfering with password protection
How did you cross-reference your data?
Triangulation (reduced errors, ensures consistency and accuracy)
E.g. I check data on relevant websites
What type of data do you handle on a day-to-day basis?
Comparables
P&L accounts
Inspection notes
Client correspondence
How is data backed up at your company?
Automatically backed up to the cloud
Protected through encryption, firewalls, passwords, disaster-recovery
Why is data important to your role and your firm?
Ensure it is accurate and up to date
Ensure we are compliant with current guidelines
Ensure we are keeping it safe for our clients - we do not want them to lose our trust
I base my valuations off a lot of it
In your example, you have used data. How do you save it?
I save it to file-naming system ensuring saved correctly, it’s accurate/updated and its password protected.
What would you do if you left your laptop somewhere with client sensitive data?
Report to the police
Inform my line manager and IT department
Report to ICO
How do you ensure data is transferred safely when your clients send it to you?
I use ‘WeTransfer’ which provides a link which expires within a few hours