Labour Day Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: geek65

PDPF Privacy and Data Protection Foundation Questions and Answers

Questions 4

What is the main purpose of the General Data Protection Regulation (GDPR)?

Options:

A.

Protecting the data of everyone in Europe.

B.

Protect the data of everyone in the world.

C.

Protect data of data subjects located in the European Economic Area (EEA), regardless of the country of processing.

D.

Protect confidential business data.

Buy Now
Questions 5

A person buys a product at a store located in the European Economic Area (EEA). At the time of purchase, you are asked to fill out a registration form and he informs his personal email.

As is usual in many stores, in the next few days this person will start receiving several marketing emails. He considers the frequency of these emails to be very high. Demanding his rights, he asks the store to delete all his personal data.

What the store must do according to the General Data Protection Regulation (GDPR)?

Options:

A.

The owner does not have this right, since he bought a product in the store, he has the right to send emails with new promotions.

B.

The store has 30 days from the date of receipt of the customer’s request to delete all data at no cost to the customer.

C.

The store must delete customer data from its advertising list. Purchase data cannot be deleted, as financial data has to be kept longer.

Buy Now
Questions 6

Data protection and privacy are closely related terms. Which of these options best represent this relationship?

Options:

A.

Privacy is a part of data protection that aims to keep personal data confidential.

B.

Data protection is a part of privacy that aims to keep personal data confidential.

C.

The two terms have the same meaning. They are synonymous.

D.

Without protection of personal data there is no privacy.

Buy Now
Questions 7

Important technical requirements set out in the General Data Protection Regulation (GDPR) are about data quality. One is the obligation to ensure appropriate security, including protection against unauthorized or unlawful processing.

What is another important technical requirement?

Options:

A.

To ascertain that personal data collection is adequate, relevant and limited to what is necessary in relation to the purposes

B.

To control that data collected for specified, explicit and legitimate purposes is not further processed for other purposes

C.

To keep personal data accurate and up to date, ensuring that inaccurate data are erased or rectified without delay

D.

To make sure that personal data is processed lawfully, fairly and in transparent manner in relation to the data subject

Buy Now
Questions 8

The GDPR states that records of processing activities must be kept by the controller. To whom must the controller make these records available, if requested?

Options:

A.

The data processor

B.

The Data Protection Officer

C.

The European Commission

D.

The supervisory authority

Buy Now
Questions 9

Which of these should appear in a Data Protection Impact Assessment (DPIA) according to the General Data Protection Regulation (GDPR)?

Options:

A.

An assessment of the need and proportionality of treatment operations in relation to the objectives.

B.

Data Protection Officer (DPO) contact and responsibilities.

C.

An inventory and the flow of personal data within the organization.

D.

A survey of other laws that must be taken into account in addition to the GDPR.

Buy Now
Questions 10

What year did the General Data Protection Regulation (GDPR) come into force?

Options:

A.

2016

B.

2018

C.

2017

D.

2019

Buy Now
Questions 11

According to the principle of purpose limitation, data should not be processed beyond the legitimate purpose defined. However, further processing is allowed in a few specific cases, provided that appropriate safeguards for the rights and freedoms of the data subjects are taken. For which purpose is further processing not allowed?

Options:

A.

For archiving purposes in the public interest

B.

For generalized statistical purposes

C.

For scientific or historical research purposes

D.

For direct marketing and commercial purposes

Buy Now
Questions 12

A company is planning to process personal data. The recently appointed data protection officer (DPO) executes a data protection impact assessment (DPIA). The DPO finds that all computers have a setting causing monitors to show a screen saver after five seconds of inaction. However, the computers are not locked automatically. When employees leave their desk, they usually do not lock their computers either. What is this an example of?

Options:

A.

Security incident

B.

Personal data breach

C.

Security vulnerability

D.

Data access

Buy Now
Questions 13

The General Data Protection Regulation (GDPR) in its Article 30 legislates on the Records of treatment activities.

If requested, the controller must provide these records:

Options:

A.

To the data processor

B.

To the Data Protection Officer (DPO)

C.

The supervisory authority

D.

To the European Commission

Buy Now
Questions 14

Which of the following has a data breach under the General Data Protection Regulation (GDPR)?

Options:

A.

A processor, after terminating its contract with the controller, deletes personal data.

B.

A collaborator goes away without locking his workstation.

C.

A backup is restored by the controller to a corrupted personal data server.

D.

A notebook with financial reports from a multinational is stolen.

Buy Now
Questions 15

Which organizations need to comply with the General Data Protection Regulation (GDPR)?

Options:

A.

Only organizations that have employees in the European Union (EU).

B.

Only organizations that have their headquarters in the European Union (EU).

C.

All organizations anywhere in the world.

D.

All organizations located in the European Union and also organizations outside the European Union that offer goods or services to data subjects in the EU.

Buy Now
Questions 16

What is the most important difference between the 95/46/EC and the GDPR?

Options:

A.

95/46/EC applies as law in all EEA member states while the GDPR is a guidance.

B.

95/46/EC applies to processing of data on EEA residents worldwide and the GDPR does not.

C.

The GDPR applies as law in all EEA member states while 95/46/EC is a guidance.

D.

The GDPR applies to persons and organizations which process personal data within EEA member states.

The scope of 95/46/EC is more restricted in this aspect.

Buy Now
Questions 17

A gentleman has a loan denied by the bank’s system that he has been a customer for many years. He is disgusted, because the loan would make it possible to hold the wedding of his only granddaughter.

He contacts the bank and asks for explanations. He wants to know exactly why his loan was denied and based on what information.

What right is required by the data subject according to the GDPR?

Options:

A.

Right to limitation of treatment

B.

Right to rectification

C.

Data subject’s right of access

D.

Right to object and automated individual decision-making

Buy Now
Questions 18

The word privacy is never mentioned in the General Data Protection Regulation (GDPR) text.

Despite this, what would be the best definition of the privacy according to the Regulation?

Options:

A.

The right not to have your life monitored by technologies.

B.

Have freedom of expression.

C.

The right to respect for private and family life, for home and communications.

D.

The right to have your personal data protected.

Buy Now
Questions 19

The General Data Protection Regulation (GDPR) is based on the principles of proportionality and subsidiarity.

What is the meaning of “proportionality” in this context?

Options:

A.

Personal data can be processed according to the use of requirements.

B.

Personal data cannot be reused without explicit and informed consent.

C.

Personal data can only be processed if there are no other means to achieve the purposes.

D.

Personal data must be adequate, relevant and not excessive in relation to the purposes.

Buy Now
Questions 20

GDPR quotes in one of its principles that personal data should be adequate, relevant and limited to what is necessary in relation to its purpose. What principle is this?

Options:

A.

integrity and confidentiality

B.

purpose limitation

C.

data minimization

D.

lawfulness, loyalty and transparency

Buy Now
Questions 21

What is the term used in the General Data Protection Regulation (GDPR) for the disclosure of, or unauthorized access to, personal data?

Options:

A.

Security incident

B.

Incident

C.

Breach of confidentiality

D.

Data breach

Buy Now
Questions 22

What is the definition of Processor according to GDPR?

Options:

A.

Individual or legal entity that is not authorized to process personal data

B.

An independent public authority created by a Member State

C.

Individual or legal entity that processes personal data on behalf of the person responsible for processing personal data.

D.

Individual or legal entity that, individually or in conjunction with others, determines the purposes and means of processing personal data.

Buy Now
Exam Code: PDPF
Exam Name: Privacy and Data Protection Foundation
Last Update: May 3, 2024
Questions: 149
PDPF pdf

PDPF PDF

$28  $80
PDPF Engine

PDPF Testing Engine

$33.25  $95
PDPF PDF + Engine

PDPF PDF + Testing Engine

$45.5  $130