What should data sources be?
verified, accurate, reliable and up-to-date
How can data be kept secured?
firewalls, passwords (being changed every 30 days), not leaving devices visible, encryption, virus protection, only individuals having access to date where necessary, backing up data, using 2-step verification.
What is an information barrier?
Could be used where different departments in the same firm are acting for 2 or more clients on the same property.
All clients must give written informed consent to manage the conflict of interest using an information barrier.
The information barrier must prevent any communication of information relevant to the instruction between the various departments, including any administrative resources.
Name a document which RICS have published regarding the use of social media?
RICS have published a regulation paper called the Use of social media: guidance for RICS members (version 1)
Name some Acts relating to data.
The Data Protection Act 2018 (UKs implementation of GDPR) and UK GDPR, Freedom of Information Act 2000
What are the 7 key principles of GDPR?
Lawfulness, fairness and transparency (1)
Purpose limitation (2)
Data minimisation (3)
Accuracy (4)
Storage limitation (5)
Integrity and Confidentiality (6)
Accountability (7)
What are the 8 individual rights under GDPR?
right to be informed
right of access
right to rectification
right to erase
right to restrict processing
right to data portability
right to object
rights concerning automated decision-making and profiling
What is the penalty for non-compliance of GDPR?
Is a fine up to the greater of £17.5M or 4% of the global annual turnover.
What is the Freedom of Information Act 2000?
This gives the public the right to request information held by public authorities, If a written request is submitted, the public body must provide a written response within 20 working days.
How long should data be stored for?
6 years. 12 years for contract under deed, subject to a 15-year long stop date.
What are the 7 principles for organisations under uk GDPR (came effect in 01 jan 2021)
Data protection act breach
£20 million or 4% of annual turnover