Pass the Exin Privacy & Data Protection PDPF Questions and answers with CertsForce

Viewing page 2 out of 5 pages
Viewing questions 11-20 out of questions
Questions # 11:

The General Data Protection Regulation (GDPR) is related to the protection of personal data. What is the definition of personal data?

Options:

A.

Preservation of confidentiality, integrity and availability of information


B.

Any information regarding an identified or identifiable natural person


C.

Any information that European citizens want to protect


D.

Data that directly or indirectly reveals racial or ethnic origins, someone’s religious views, and their data related to sexual health and habits


Expert Solution
Questions # 12:

After appearing in a photo posted by a friend on a social network, a person felt embarrassed and decided that he wants the photo to be deleted.

According to the General Data Protection Regulation (GDPR), does that person have the right to delete this photo?

Options:

A.

False


B.

True


Expert Solution
Questions # 13:

On July 12, 2016 the European Commission implemented a ruling regarding the transfer of personal data between the EEA and the US. The ruling is based on the data protection measures described in the EU-US Privacy Shield. What kind of a ruling is this?

Options:

A.

Derogation


B.

Legally binding contract


C.

Treaty superseding the GDPR


D.

Adequacy decision


Expert Solution
Questions # 14:

A person who works for a union took home a draft newsletter to finish it. The thumb drive containing the draft and contact list has been lost. To whom, among others, this data breach should be reported?

Options:

A.

To all members of the contact list


B.

To the Union staff


C.

To the police


Expert Solution
Questions # 15:

What does the principle of ‘data minimization’ mean?

Options:

A.

Personal data shall be accurate and where necessary kept up to date.


B.

Personal data shall be adequate and limited to what is necessary for the purposes of the processing.


C.

Personal data shall be processed in a manner that ensures appropriate security of the personal data.


D.

Personal data shall be processed lawfully, fairly and in a transparent manner in relation to the data subject.


Expert Solution
Questions # 16:

While performing a backup, a data server disk crashed. Both the data and the backup are lost. The disk contained personal data, but no special category personal data. The processor states that this is a personal data breach. Is the statement of the processor true?

Options:

A.

Yes, because there were no special category personal data stored on the disk.


B.

No, because no personal data on the disk were processed, only destroyed


C.

Yes, because the personal data on the disk were unlawfully processed.


D.

No, because this is only a security incident and not a data breach


Expert Solution
Questions # 17:

A personal data breach has occurred, and the controller is writing a draft notification for the supervisory authority. The following information is already in the notification:

-The nature of the personal data breach and its possible consequences.

-Information regarding the parties that can provide additional information about the data breach.

What other information must the controller provide?

Options:

A.

Information of local and national authorities that were informed about the data breach.


B.

Name and contact details of the data subjects whose data may have been breached


C.

Suggested measures to mitigate the adverse consequences of the data breach.


D.

The information needed to access the personal data that have been breached.


Expert Solution
Questions # 18:

The Control Authority may impose fines on organizations that are not meeting the mandatory requirements of the General Data Protection Regulation (GDPR).

Options:

A.

False


B.

True


Expert Solution
Questions # 19:

What is the relationship between data protection and privacy?

Options:

A.

Data protection and privacy are synonyms and have the same meaning.


B.

Data protection refers to the measures needed to protect a person’s privacy.


C.

Data protection is the part of privacy that protects a person’s physical integrity.


Expert Solution
Questions # 20:

According to the GDPR, for which situations should a Data Protection Impact Assessment (DPIA) be conducted?

Options:

A.

For all projects that include technologies or processes that require data protection


B.

For all sets of similar processing operations with comparable risks


C.

For any situation where technologies and processes will be subject to a risk assessment


D.

For technologies and processes that are likely to result in a high risk to the rights of data subjects


Expert Solution
Viewing page 2 out of 5 pages
Viewing questions 11-20 out of questions