What is GDPR?
EU General Data Protection Regulation
What is the purpose of GDPR?
Protect citizens personal data
What constitutes personal data?
Any information related to a person or ‘Data Subject’ that can be used to identify a person EG names, photo, email address, bank details etc
Examples of personal data under GDPR that could apply to property companies?
To what organisations does GDPR apply?
The UK GDPR applies to ‘controllers’ and ‘processors’.
A controller determines the purposes and means of processing personal data.
A processor is responsible for processing personal data on behalf of a controller.
What are penalties for GDPR breaches?
4% of annual global turnover up to 20 million euros
What is the ‘right to access’ under GDPR?
Individuals have the right to obtain confirmation that their data is being processed, and access to their personal data
What is a breach notification under GDPR?
How are data breaches typically discovered?
Access logs, reported thefts, lost equipment or data security incident
How have consent conditions been strengthened under GDPR?
What is ‘right to be forgotten’ under GDPR?
Under Article 17 of GDPR, individuals have right to have personal data erased in certain circumstances where…
- Data no longer necessary
- Data been processed unlawfully
What is data portability?
Right for data subject to receive personal data concerning them which they have previously provided, and have it transmitted to another controller
What is privacy by design?
What is data protection officer?
Examples of data held by surveying practices?
What are obligations imposed by GDPR?
Who regulates GDPR in the UK?
Information Commissioners Office
RICS best practice points for complying with GDPR?
What are your company’s policies for data protection breaches?
Report to line manager or Data Protection Officer within the firm
RICS recommendations for using confidential information?
What information should be included in firms privacy notice?
When did GDPR come into effect
25 May 2018
What Act implemented GDPR in the UK?
What are the key requirements of GDPR?