Pass the Exin Privacy & Data Protection PDPF Questions and answers with CertsForce

Viewing page 4 out of 5 pages
Viewing questions 31-40 out of questions
Questions # 31:

What is the purpose of Data Lifecycle Management (DLM)?

Options:

A.

Ensure data integrity and its periodic update


B.

Ensure data confidentiality and availability throughout its useful life.


C.

Ensure that the processing of personal data, throughout its useful life complies with the GDPR


D.

Ensure data confidentiality throughout its useful life, from collection to deletion.


Expert Solution
Questions # 32:

A security breach has occurred in an information system that also holds personal data. According to the GDPR, what is the very first thing the controller must do?

Options:

A.

Assess the risk of adverse effects to the data subjects using a data protection impact assessment (DPIA)


B.

Ascertain whether the breach may have resulted in loss or unlawful processing of personal data


C.

Report the breach immediately to all data subjects and the relevant supervisory authority


D.

Assess whether personal data of a sensitive nature has or may have been unlawfully processed


Expert Solution
Questions # 33:

Which of the options below best represents data protection by design?

Options:

A.

It aims to incorporate security measures to protect data from the moment it is collected, throughout the processing and until its destruction at the end of the process


B.

It aims to ensure that personal data is automatically part of a protection process.


C.

It aims to create privacy impact analysis procedures (DPIA), notifications of breaches of privacy and fulfil requests from data subjects.


Expert Solution
Questions # 34:

In its Article 9 the GDPR categorizes some types of personal data as “sensitive”.

Of these below which are considered sensitive?

Options:

A.

Date of birth of a person.


B.

A person’s home address.


C.

Soccer team that a person supports.


D.

Result of a medical examination.


Expert Solution
Questions # 35:

The General Data Protection Regulation (GDPR) allows processing of personal data only for purposes explicitly permitted by law. A tax advisor wants to file income tax returns for a neighbor.

Which of the legitimate grounds in the GDPR applies?

Options:

A.

Processing of the personal data is permitted in this case with explicit consent of the data subject.


B.

Processing of the personal data is permitted because this is necessary for compliance with a legal obligation to which the controller is subject.


C.

Processing of personal data is permitted in the course of a purely personal or household activity.


Expert Solution
Questions # 36:

GDPR quotes in one of its principles that personal data should be adequate, relevant and limited to what is necessary in relation to its purpose. What principle is this?

Options:

A.

integrity and confidentiality


B.

purpose limitation


C.

data minimization


D.

lawfulness, loyalty and transparency


Expert Solution
Questions # 37:

A company wishes to use personal data of their customers. They wish to start sending all female customers a customized newsletter. What right do all data subjects have in this scenario?

Options:

A.

The right to rectification


B.

The right to compensation


C.

The right to object to profiling


Expert Solution
Questions # 38:

What is the role of the one assigned the responsibility to govern the purposes and means of processing personal data within an organization, according to the GDPR?

Options:

A.

Controller


B.

Data Protection Officer


C.

Data Subject


D.

Processor


Expert Solution
Questions # 39:

When a data breach occurs in a company that has branches in several countries of the European Union, which supervisory authority is competent to take the appropriate measures?

Options:

A.

The Supervisory Authority of the country where the company’s main establishment is located.


B.

The Supervisory Authority of the country where the subsidiary with the largest number of affected holders

is located.


C.

The Supervisory Authority of the country that had the most affected holders.


D.

The Supervisory Authority of the country where the company’s largest subsidiary is located.


Expert Solution
Questions # 40:

What is a description of data protection by design and by default?

Options:

A.

Not holding more data than is strictly required for processing


B.

An indication of timeframes if processing relates to erasure


C.

Data may only be collected for explicit and legitimate purposes


D.

An approach that implements data protection from the start (Correct)


Expert Solution
Viewing page 4 out of 5 pages
Viewing questions 31-40 out of questions