Labour Day Special Limited Time Flat 70% Discount offer - Ends in 0d 00h 00m 00s - Coupon code: 70spcl

Exin PDPF Privacy and Data Protection Foundation Exam Practice Test

Page: 1 / 15
Total 149 questions

Privacy and Data Protection Foundation Questions and Answers

Question 1

After notifying the supervisory authority, what should be the first action the controller must take when it finds a security breach where unauthorized people have accessed personal data?

Options:

A.

Contact the DPO for formal notification to the Supervisory Authority.

B.

Analyze whether sensitive data has been accessed.

C.

Register a Police Report at the cybercrime station.

D.

Notify data subjects that have been subject to a security breach.

Question 2

After appearing in a photo posted by a friend on a social network, a person felt embarrassed and decided that he wants the photo to be deleted.

According to the General Data Protection Regulation (GDPR), does that person have the right to delete this photo?

Options:

A.

False

B.

True

Question 3

In what way are online activities of people most effectively used by modern marketers?

Options:

A.

By analyzing the logs of the web server it can be seen which products are top sellers, allowing them to optimize their marketing campaigns for those products.

B.

By tagging users of social media, profiles of their online behavior can be created. These profiles are used to ask them to promote a product.

C.

By tagging visitors of web pages, profiles of their online behavior can be created. These profiles are sold and used in targeted advertisement campaigns.

Question 4

The Control Authority may impose fines on organizations that are not meeting the mandatory requirements of the General Data Protection Regulation (GDPR).

Options:

A.

False

B.

True

Question 5

The General Data Protection Regulation (GDPR) is often known as the “European privacy law”. What is the relationship between ‘privacy’ and ‘data protection’?

Options:

A.

Privacy is a part of data protection that aims to keep personal data confidential.

B.

Data protection is a part of privacy that aims to keep personal data confidential.

C.

The two terms have the same meaning. They are synonyms.

D.

Data protection is the necessary measures to protect an individual’s privacy.

Question 6

According to the principle of purpose limitation, data should not be processed beyond the legitimate purpose defined. However, further processing is allowed in a few specific cases, provided that appropriate safeguards for the rights and freedoms of the data subjects are taken. For which purpose is further processing not allowed?

Options:

A.

For archiving purposes in the public interest

B.

For generalized statistical purposes

C.

For scientific or historical research purposes

D.

For direct marketing and commercial purposes

Question 7

A written contract between a controller and a processor is called a data processing agreement. According to

the GDPR, what does not have to be covered in the written contract?

Options:

A.

The contractor code of business ethics and conduct that is used.

B.

Which data are covered by the data processing agreement

C.

The information security and personal data breach procedures

D.

The technical and organizational measures implemented

Question 8

What is a responsibility of Supervisory Authorities in EEA countries?

Options:

A.

Research on security breaches of corporate information

B.

Supervision of all data processing operations controlled by a controller in an EEA country

C.

Supervision of all data processing operations where the data subjects are residents of an EEA country

Question 9

What year did the General Data Protection Regulation (GDPR) come into force?

Options:

A.

2016

B.

2018

C.

2017

D.

2019

Question 10

When does the GDPR require data subjects consent to a cookie?

Options:

A.

Always, because a cookie is regarded as online identifier

B.

Never, as the EU Cookie Law does not require explicit consent

C.

Only if the cookie contains authentication information of the data subject

D.

Only if the cookie contains shopping basket items

Question 11

Which condition below allows personal data to be processed legally?

Options:

A.

A Data Privacy Impact Assessment (DPIA) should be performed prior to data collection.

B.

Data processing must be previously authorized by the Supervisory Authority.

C.

Holders’ rights must be protected by a privacy policy.

D.

There must be a legitimate basis for data processing.

Question 12

While paying with a credit card, the card is skimmed (i.e. the data on the magnetic strip is stolen). The magnetic strip contains the account number, expiration date, cardholder’s name and address, PIN number and more.

What kind of a data breach is this?

Options:

A.

Material

B.

Non-material

C.

Verbal

Question 13

According to the GDPR, in what situation must data subjects always be notified of a personal data breach?

Options:

A.

When personal data is processed at a facility of the processor that is not located within the borders of the EEA

B.

When personal data is processed by a party that agreed to the draft processing contract but has not yet signed it

C.

When the system on which the personal data is processed is attacked causing damage to its storage devices

D.

When there is a significant probability that the breach will lead to a high risk for the privacy of the data subjects

Question 14

Which EU legislation allows data to be transferred between the European Economic Area (EEA) and the United States (USA)?

Options:

A.

A suitability decision based on the Privacy Shield program

B.

A transfer made on the basis of World Trade Organization legislation.

C.

European Union Directive 95/46 / EC.

D.

A transfer made under UN law.

Question 15

What is the relationship between data protection and privacy?

Options:

A.

Data protection and privacy are synonyms and have the same meaning.

B.

Data protection refers to the measures needed to protect a person’s privacy.

C.

Data protection is the part of privacy that protects a person’s physical integrity.

Question 16

Personal data can be transferred outside of the EEA. According to the GDPR, which transfers outside the EEA are always lawful?

Options:

A.

Transfers based on the laws of the non-EEA country concerns

B.

Transfers falling under World Trade Organization rules

C.

Transfers governed by approved binding corporate rules (BCR)

D.

Transfers within a global corporation or organization

Question 17

What is considered a personal data processing for the General Data Protection Regulation (GDPR)?

Options:

A.

Analysis of data regarding the cause of death in the last 10 years.

B.

Creating a backup with records of names, addresses, enrollment of students.

C.

Conducting analysis of personal data related to health issues, but which have previously been anonymized.

D.

Statistical publication with intention to vote, help anonymously.

Question 18

The GDPR contains several items. Which of these contains mandatory requirements?

Options:

A.

Recitals

B.

Articles

Question 19

A person finds that a private videotape showing her in a very intimate situation has been published on a website. She never consented to publication and demands that the video is being removed without undue delay.

According to the GDPR, what should be done next?

Options:

A.

Nothing. The video may be regarded as ‘news’ and, therefore, the website is only exercising its right to freedom of expression and information.

B.

The controller erases the video from the website and, when possible, informs any controller who might

process the same video, that it must be erased.

C.

The controller erases the video from the website. There is no obligation however, to inform others who might have copied it, that it should be erased.

D.

The controller directs the person to seek a lawyer and informs that he cannot exclude before a juridical authorization.

Question 20

Which of the options below is classified as a personal data breach under the GDPR?

Options:

A.

Personal data processed without the consent of the controller.

B.

A server is attacked and exploited by a hacker.

C.

Data accessed by employees without permission.

D.

Strategic company data is mistakenly shared.

Question 21

The General Data Protection Regulation (GDPR) in its Article 30 legislates on the Records of treatment activities.

If requested, the controller must provide these records:

Options:

A.

To the data processor

B.

To the Data Protection Officer (DPO)

C.

The supervisory authority

D.

To the European Commission

Question 22

What is the main reason for performing data protection by design (from conception)?

Options:

A.

Develop technical measures for the protection of personal data.

B.

Enable better marketing campaigns targeted at customers.

C.

Collect as much data as possible for data processing.

D.

Reduce the risk of not meeting legal obligations.

Page: 1 / 15
Total 149 questions