What is GDPR?
When did GDPR come into effect?
25th May 2018 - same day is data Protection Act
(Incorporated as part of new EU GDPR legislation)
Who regulates GDPR in the UK?
Information Commissioners Office (ICO)
Key persons outlined in GDPR?
Controller - decides how and why personal data is used
Processor - Handles personal data on behalf of controller
Data officer - Oversees data protection and ensures compliance with rules
What is the purpose of GDPR?
Protect citizens information
What constitutes personal data?
Information that is used to identify a person or data subject e.g photos, names, email address
Examples of personal data under GDPR that could apply to property companies?
Data relating;
- Background checks by HR
- Investors
- Fund managers
- Valuations
- Compliance
What Act implemented GDPR in the UK?
What are the 7 principles of Data Protection Act 2018? (AKA 7 principles of GDPR) LAAPSID
8 individual rights under GDPR? (IARERDOA)
To what organisations does GDPR apply?
Any and all businesses and organisations responsible for holding data in the EU
What are penalties for GDPR breaches?
What is the ‘right to access’ under GDPR?
What is a breach notification under GDPR?
How are data breaches typically discovered?
How have consent conditions been strengthened under GDPR?
What is ‘right to be forgotten’ under GDPR?
What is data portability?
Right to obtain and reuse personal data across different services or distributed to a new controller
What is privacy by design?
What is data protection officer?
Examples of data held by surveying practices?
What are obligations imposed by GDPR?
RICS best practice points for complying with GDPR?
What are your company’s policies for data protection breaches?