How long do you need to keep data for?
6 years if the contract is signed underhand.
12 years if the contract is executed as a deed.
Limitation Act 1980 sets most legal claim limitation periods.
Royal Institution of Chartered Surveyors recommends retaining data for up to 15 years.
What type of data systems are used in your organisation?
Shared hard drives.
Backup servers.
Online storage systems (e.g. Dropbox).
Collaboration software such as Microsoft Teams.
Project extranet.
What is a project extranet system?
A computer network that allows external parties to view project files on a secure platform.
Advantages
Improves communication.
24-hour access.
Efficient document sharing.
Secure access with permission settings.
Disadvantages
Can be expensive.
Requires maintenance.
May require user training.
What are the benefits of cloud-based storage systems?
Easy access anywhere in the world.
Secure and password protected.
Low set-up cost.
Teams can work in real time.
Access controls and restrictions for confidential files.
What sources of pricing data are available?
BCIS.
Pricing books such as Spons.
Benchmarking.
In-house records and databases.
What are pricing books?
Used to assist with estimating and valuing variations.
Cover major areas of the construction process.
Include rates for maintenance, refurbishment and new build work.
Used for both large and small projects.
What is BCIS?
Building Cost Information Service.
Provides construction cost and price data for the UK industry.
Used to produce estimates and option appraisals.
Supports early cost advice and cost planning.
Provides benchmarks for projects.
Part of the Royal Institution of Chartered Surveyors.
What is the Data Protection Act 2018?
UK legislation controlling how personal information is used by organisations, businesses and government.
It is the UK’s implementation of the General Data Protection Regulation.
What is GDPR?
A regulation in EU law on data protection and privacy.
Applies to the European Union and European Economic Area.
Governs how personal data is processed and protected.
Also regulates the transfer of personal data outside the EU/EEA.
What is the purpose of GDPR?
To harmonise data privacy laws across member states.
To strengthen protection and rights of individuals.
To regulate how organisations collect, process and store personal data.
Non-compliance can result in significant fines and reputational damage.
Who are the key persons outlined within GDPR?
Data Controller
Person or organisation that determines how and why personal data is processed.
Data Processor
A person or organisation that processes data on behalf of the controller.
Data Subject
The individual whose personal data is being processed.
Data Protection Officer (DPO)
Responsible for monitoring compliance with data protection regulations.
What constitutes personal data?
Any information relating to an identifiable individual (data subject).
Can identify a person directly or indirectly.
Examples
Name
Photograph
Email address
Bank details
Social media posts
Medical information
IP address
Applies to electronic data and searchable physical records.
What is the difference between a data processor and a data controller?
Data Controller
Determines the purposes, conditions and means of processing personal data.
Data Processor
Processes personal data on behalf of the controller.
What are the 7 key principles of GDPR?
What are the 8 individual rights under GDPR?
Who enforces GDPR in the UK?
Information Commissioner’s Office.
What is the Freedom of Information Act 2000?
Provides public access to information held by public authorities.
Public authorities must publish certain information about their activities.
Members of the public can request information from public authorities.
If you intend to destroy a document, what should you consider beforehand?
Is the document an original contract or legal document?
Could it be required for litigation or legal proceedings?
Does the document relate to a live project?
Is a backup copy available?
What measures could be taken to protect commercially sensitive information?
Have a Non-Disclosure Agreement (NDA) in place.
Physically separate staff where required.
Secure document storage (locked cabinets and password-protected systems).
How can you protect data when transferring it on a client’s behalf?
Encryption and password protection.
Recorded or secure delivery methods.
Clearly mark documents as confidential.
Use secure networks and software.
What is an information barrier?
A physical and/or electronic separation of individuals within the same firm.
Used to prevent confidential information being shared between teams.