Pass the Exin Privacy & Data Protection PDPF Questions and answers with CertsForce

Viewing page 3 out of 5 pages
Viewing questions 21-30 out of questions
Questions # 21:

Who is responsible for demonstrating the compliance of personal data processing with the General Data Protection Regulation (GDPR)?

Options:

A.

The Data Protection Officer (DPO)


B.

The processor


C.

The controller


D.

The supervisory authority


Expert Solution
Questions # 22:

The word privacy is never mentioned in the General Data Protection Regulation (GDPR) text.

Despite this, what would be the best definition of the privacy according to the Regulation?

Options:

A.

The right not to have your life monitored by technologies.


B.

Have freedom of expression.


C.

The right to respect for private and family life, for home and communications.


D.

The right to have your personal data protected.


Expert Solution
Questions # 23:

Which condition below allows personal data to be processed legally?

Options:

A.

A Data Privacy Impact Assessment (DPIA) should be performed prior to data collection.


B.

Data processing must be previously authorized by the Supervisory Authority.


C.

Holders’ rights must be protected by a privacy policy.


D.

There must be a legitimate basis for data processing.


Expert Solution
Questions # 24:

What is the definition of Processor according to GDPR?

Options:

A.

Individual or legal entity that is not authorized to process personal data


B.

An independent public authority created by a Member State


C.

Individual or legal entity that processes personal data on behalf of the person responsible for processing personal data.


D.

Individual or legal entity that, individually or in conjunction with others, determines the purposes and means of processing personal data.


Expert Solution
Questions # 25:

What is the main reason for performing data protection by design (from conception)?

Options:

A.

Develop technical measures for the protection of personal data.


B.

Enable better marketing campaigns targeted at customers.


C.

Collect as much data as possible for data processing.


D.

Reduce the risk of not meeting legal obligations.


Expert Solution
Questions # 26:

What is the main objective of the “Lifecycle Protection” principle?

Options:

A.

All appropriate measures shall be taken to ensure that inaccurate data, taking into account the purposes for which they are processed, are erased or rectified without a delay.


B.

The processing of data must take place in a manner that ensures its security, including protection against unauthorized or unlawful processing and accidental loss, destruction or damage.


C.

Security measures should be in place from the moment data are collected until they are deleted.


D.

Data must be collected for specified, explicit and legitimate purposes and may not be further processed in a manner incompatible with those purposes.


Expert Solution
Questions # 27:

Who should ask for an opinion after conducting an impact assessment on the protection of personal data (DPIA)?

Options:

A.

DPO


B.

Controller


C.

Supervisory Authority


D.

Processor


Expert Solution
Questions # 28:

According to the GDPR, what is a description of binding corporate rules (BCR)?

Options:

A.

A decision on the safety of transferring personal data to a non-EEA country


B.

A set of approved rules on personal data protection used by a group of enterprises


C.

A measure to compensate for the lack of personal data protection in a third country


D.

A set of agreements covering personal data transfers between non-EEA countries


Expert Solution
Questions # 29:

To plan the amount of parking space needed, a local government monitors and saves the license plate number of every car that enters and leaves the city center. They have obtained permission to collect data on the number of cars present in the city center. By comparing the license plate time of entry and exit the number of cars present every moment of each day is calculated. Each month a report is created detailing the average number of cars in the city center at specific moments for every day of the week. At every entrance to the city center, a billboard clearly states what data is collected by whom, the purpose of the processing and the fact that the license plate numbers are saved securely for up to two years, because the measurements will be repeated next year. Which of the basic principles for legitimate processing of personal data is violated in this scenario?

Options:

A.

Personal data are processed in a manner that ensures appropriate security of the personal data.


B.

Personal data are processed in a transparent manner in relation to the data subject


C.

Personal data are kept in a form permitting identification of data subjects for no longer than is necessary.


D.

Personal data are collected for specified, explicit and legitimate purposes and not further processed.


Expert Solution
Questions # 30:

According to the GDPR, what is the main reason to consider data protection in the initial design phase?

Options:

A.

It ensures efficiency in project phases


B.

It ensures privacy by default


C.

It reduces the risk of fraud


D.

It reduces the risk of liability


Expert Solution
Viewing page 3 out of 5 pages
Viewing questions 21-30 out of questions