Pass the Exin Privacy & Data Protection PDPF Questions and answers with CertsForce

Viewing page 1 out of 5 pages
Viewing questions 1-10 out of questions
Questions # 1:

The GDPR describes the principle of data minimization. How can organizations comply with this principle?

Options:

A.

By applying the concept of least privilege to the personal data collected, stored or otherwise processed.


B.

By limiting access rights to staff who need the personal data for the intended processing operations


C.

By limiting the personal data to what is adequate, relevant and necessary for the processing purposes


D.

By limiting file sizes, through saving all personal data that is processed in the smallest possible format


Questions # 2:

Which of these options is an example of a data breach?

Options:

A.

Transfer of personal data outside the EU


B.

Loss of personal data


C.

A security incident related to corporate data.


Questions # 3:

Which of the following has a data breach under the General Data Protection Regulation (GDPR)?

Options:

A.

A processor, after terminating its contract with the controller, deletes personal data.


B.

A collaborator goes away without locking his workstation.


C.

A backup is restored by the controller to a corrupted personal data server.


D.

A notebook with financial reports from a multinational is stolen.


Questions # 4:

What is the definition of Supervisory Authority according to the GDPR?

Options:

A.

Individual or legal entity processing personal data on behalf of the person responsible for processing personal data.


B.

An independent public authority created by a Member State.


C.

Individual or legal entity that is not authorized to process personal data


D.

Individual or legal entity that, individually or in conjunction with others, determines the purposes and means of processing personal data.


Questions # 5:

A person buys a product at a store located in the European Economic Area (EEA). At the time of purchase, you are asked to fill out a registration form and he informs his personal email.

As is usual in many stores, in the next few days this person will start receiving several marketing emails. He considers the frequency of these emails to be very high. Demanding his rights, he asks the store to delete all his personal data.

What the store must do according to the General Data Protection Regulation (GDPR)?

Options:

A.

The owner does not have this right, since he bought a product in the store, he has the right to send emails with new promotions.


B.

The store has 30 days from the date of receipt of the customer’s request to delete all data at no cost to the customer.


C.

The store must delete customer data from its advertising list. Purchase data cannot be deleted, as financial data has to be kept longer.


Questions # 6:

An Independent Supervisory Authority has several responsibilities. Which of the following is one of these?

Options:

A.

Supervise the application of the General Data Protection Regulation (GDPR).


B.

Assist in the elaboration and adaptation of the specific data protection laws of each country.


C.

Conduct a Data Protection Impact Assessment (DPIA).


D.

Assist in the planning of a Personal Data Protection Management System when requested by the Controller.


Questions # 7:

According to the GDPR, in what situation must data subjects always be notified of a personal data breach?

Options:

A.

When personal data is processed at a facility of the processor that is not located within the borders of the EEA


B.

When personal data is processed by a party that agreed to the draft processing contract but has not yet signed it


C.

When the system on which the personal data is processed is attacked causing damage to its storage devices


D.

When there is a significant probability that the breach will lead to a high risk for the privacy of the data subjects


Questions # 8:

The Supervisory Authority is notified whenever an organization intends to process personal data, except for some specific situations. The Supervisory Authority keeps a publicly accessible register of these data processing operations.

What else is a legal obligation of the Supervisory Authority in reaction to such a notification?

Options:

A.

To assess compliance with the law in all classes where sensitive personal data is processed


B.

To assess the legitimacy of operations that involve specific risks for the data subjects


C.

To assess the legitimacy of binding contract(s) between the controller and the data processor(s)


D.

To give out a license for the data processing, specifying the types of personal data which are allowed


Questions # 9:

A controller wants to switch processors. What is necessary to review before making this change, so that it remains GDPR compliant?

Options:

A.

The matrix location of this new processor.


B.

Require the old processor to erase data.


C.

Require the old processor to port the data.


D.

Verify that the new processor has sufficient security guarantees.


Questions # 10:

Which organizations need to comply with the General Data Protection Regulation (GDPR)?

Options:

A.

Only organizations that have employees in the European Union (EU).


B.

Only organizations that have their headquarters in the European Union (EU).


C.

All organizations anywhere in the world.


D.

All organizations located in the European Union and also organizations outside the European Union that offer goods or services to data subjects in the EU.


Viewing page 1 out of 5 pages
Viewing questions 1-10 out of questions