Data Management (L1) Flashcards

(20 cards)

1
Q

What are the key pieces of legislation relating to Data management?

A

Freedom of Information Act 2000
CRCA 2005
Data Protection Act 2018
UK GDPR

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is the relationship between UK GDPR and the Data Protection Act 2018?

A

DPA 2018 supplements UK GDPR

UK GDPR is the retained version of EU GDPR following Brexit

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is the Freedom of Information Act 2000?

Timeframe for info to be provided?

A

Gives public legal right to access information held by public authorities.

Must be provided within 20 working days, subject to exemptions.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is the purpose of the Data Protection Act 2018?

A

Supplements UK GDPR

Controls how personal data is used by businesses

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are the 7 data protection principles from the Data Protection Act 2018?

(LADPASS)

A

Lawfulness, fairness, transparency
Accuracy
Data minimisation
Purpose limitation
Accountability
Storage limitation
Security

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What are the 8 individual rights in the Data Protection Act 2018?

(AO RAIDER)

A

Access
Object

Rectification
Automated decision making / profiling
Informed
Data portability
Erasure
Restrict processing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is CRCA 2005?

A

Commissioners for Revenue and Customs Act 2005

Applies to all HMRC officers - provides duty to keep information confidential

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is in section 10 of CRCA 2005?

A

Explicit to VOA - allows ‘officers of revenue and customs’ to provide valuation of property for HMRC, public authorities, or functions in connection with public purposes.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is in section 17 of CRCA 2005?

A

Allows sharing of information between HMRC and VOA.

(e.g. SDLTs, RALDs)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is in section 18 of CRCA 2005?

A

Permits disclosure of information outside VOA/HMRC in line with function.

(e.g. RALDs to agent)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is in section 19 of CRCA 2005?

A

Makes it a criminal offence to disclose information that can identify an individual, unless covered by s18.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What personal data is protected under GDPR?

A

Information relating to an individual.
Examples:
- Name
- Home address
- Email address
- ID card number
- Phone number
- IP address

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Who are the key persons outlined within GDPR?

A

Controller – determines purposes and means of processing personal data.

Processor – processes personal data on behalf of controller.

Data Protection Officer (DPO) – leadership role required by EU GDPR - oversees data protection approach.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Imagine you’ve identified a potential data breach while working at the VOA. Who would you report this to, and what statutory reporting requirements or deadlines would apply in this situation?

A

Report breach (internally) within 72 hours of becoming aware. Data Protection Officer (DPO) required for public authorities.

If breach has high likelihood to risk people’s rights and freedoms - Report to Information Commissioner’s Office (ICO) within 72 hours.

Stronger legal protection for more sensitive information, such as race, religious or political beliefs, sexual orientation.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is the maximum fine for a data breach under UK GDPR?

A

20 million euros or 4% annual global turnover

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What are the advantages of storing property related documents in a secure network drive?

(ABC)

A

o Access management

o Backup and Recovery

o Compliance

17
Q

In what circumstances can a Freedom of Information (FOI) request be refused?

Freedom of Information Act 2000

A
  • Cost and time.
  • Vexatious request.
  • Repeated request.
  • Contrary to GDPR.
  • Disclosing the information would prejudice (harm) a criminal investigation or law enforcement.
18
Q

Can the VOA disclose property related information (e.g. general sales, rental information, property attributes)?

Which legislation does this relate to?

A

No - it could identify an individual.

Freedom of Information Act 2000

19
Q

Hypothetically, what would you do if you lost a flash drive containing a client’s personal information?

A

Report breach to DPO within 72 hours of becoming aware.

If breach has high likelihood to risk people’s rights and freedoms - Report to Information Commissioner’s Office (ICO) within 72 hours.

Also let client know and (if data had been sent to another party incorrectly) contact other party to request deletion.

20
Q

You have mentioned that you regularly research, gather and analyse data from external sources.

As an example of this, if you find a rental transaction on CoStar, how can you verify the accuracy of the data?

A

Cross-check against multiple sources, such as:
- other databases (EIG, internal records)
- agent information (brochures / particulars, market listings)
- direct verification (call/email agent)

Also apply professional judgement to assess reliability.