Pass the BCS BCS Practitioner PDP9 Questions and answers with CertsForce

Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions
Questions # 1:

An investigation reveals that an individual is defrauding a public authority After a (suspected) tip off from a senior manager, the individual submits a Subject Access Request to the authority asking for a copy of all personal data relating to any investigations that have been carried out

What would be the BEST approach?

Options:

A.

The legal and professional privilege exemption applies to this information, and therefore the information does not need to be disclosed


B.

They do not need to disclose details of the investigation as they can rely on the crime and taxation exemption on the basis that disclosure would prejudice the investigation


C.

This is criminal offence data and therefore under the provisions of the Data Protection Act 2018, there is no obligation to disclose


D.

While the right to inform does not apply in relation to criminal acts, they need to disclose the information as this has not yet been passed to the police.


Expert Solution
Questions # 2:

If a complainant disagrees with the decision of the UK's supervisory authority, how do they appeal this decision?

Options:

A.

To the First Tier Tribunal (Information Rights)


B.

To the Information Commissioner


C.

To the European Data Protection Supervisor.


D.

To the European Commission


Expert Solution
Questions # 3:

What does NOT have an exemption prescribed under schedule 3 of the Data Protection Act 2018?

Options:

A.

Education data, examination scripts and marks


B.

Credit checking agency data


C.

Social Work Data.


D.

Health data


Expert Solution
Questions # 4:

Where a processor engages another processor ("sub-processor") to carry out processing activities on behalf of a controller, which of the following statements is CORRECT?

Options:

A.

The processor must receive prior written authorisation to use the sub-processor


B.

The processor may use the sub-processor without the written authorisation of the controller if it adheres to an approved code of conduct


C.

The processor may use the sub-processor without the written authorisation of the controller if the sub-processor signs a contract which reflects the same obligations as the contract with the controller


D.

The processor may use the sub-processor without the written authorisation of the controller if the processing is deemed to be low risk.


Expert Solution
Questions # 5:

Of the following options which is NOT a purpose of carrying out a Data Protection Impact Assessment (DPIA)?

Options:

A.

It is necessary to fulfil the requirement that all DPIAs are submitted to the ICO


B.

It is key to the accountability element of the GDPR.


C.

It fulfils a requirement that data protection is carried out by design and default.


D.

It assists in identifying the main risks that may exist in any use of data, so that they can be mitigated


Expert Solution
Questions # 6:

What is the meaning of storage limitation in relation to UK GDPR Article 5 (1 )(e)?

Options:

A.

Keeping identifiable personal data for no longer than is necessary for the intended processing


B.

Storing data in a secure format only permitting access to those with a business need


C.

Only storing data in locations within the EU. except where there is an adequacy decision.


D.

Limiting the number of records stored in any single repository to minimise risk surface.


Expert Solution
Questions # 7:

Which of the following statements MOST accurately describes the potential impact of Al on the principle of transparency?

Options:

A.

Data subjects should generally expect Al to be present in processing activities


B.

Transparency requirements do not apply to Al, as it is always compatible with original purposes


C.

Al can lead to invisible processing, with data subjects not being aware of its presence.


D.

Transparency requirements do not apply to Al, as there is a relevant exemption


Expert Solution
Questions # 8:

What are Information Society Services'? Select the INCORRECT answer

Options:

A.

A service provided for remuneration, by electronic means, at distance to an individual that has requested it.


B.

An electronic information service provided to individuals but paid for solely by advertising


C.

Business to business online networking sites


D.

Information services provided by non-profit or government organisations with no remuneration


Expert Solution
Questions # 9:

You are a consulting Data Protection Officer (DPO) for a holiday resort You have been asked to conduct a Data Protection Impact Assessment (DPIA) for them in advance of adopting a new HR management database.

While working through the DPIA, which of the following is NOT a requirement?

Options:

A.

Describe the processing


B.

Sign off and record outcomes.


C.

Identify measures to mitigate the risks


D.

Publish any potential risks in your information notice.


Expert Solution
Questions # 10:

What factors should be considered when looking at security of processing under Article 32 of the GDPR?

Select the INCORRECT answer

Options:

A.

Lawfulness of processing


B.

The most secure option available


C.

The likelihood of a risk to the rights of the data subjects


D.

Adherence to an approved code of conduct


Expert Solution
Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions