Black Friday Special 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: best70

PDPF Privacy and Data Protection Foundation Questions and Answers

Questions 4

A company’s director’s notebook is accidentally wet, which permanently damages the equipment so that it cannot recover its data.

The lost data concerned the financial reports of the company. What happened in this case according to GDPR?

Options:

A.

A vulnerability

B.

A threat

C.

A security incident

D.

A data violation

Buy Now
Questions 5

Which EU legislation allows data to be transferred between the European Economic Area (EEA) and the United States (USA)?

Options:

A.

A suitability decision based on the Privacy Shield program

B.

A transfer made on the basis of World Trade Organization legislation.

C.

European Union Directive 95/46 / EC.

D.

A transfer made under UN law.

Buy Now
Questions 6

A controller asks a processor to produce a report containing customers who have purchased a particular product more than once in the past 6 months.

The processor provides services to several companies (which in this case are the controllers).

When generating the requested report, it uses customer data collected by another controller, that is, for a different purpose.

Fortunately, the error is noticed in time, the report is not sent, and nobody has had access to this data. In this case, how does the processor need to proceed and what action should the controller take?

Options:

A.

The processor notifies the Supervisory Authority that a violation has occurred. The controller will be notified and must perform a Data Protection Impact Assessment (DPIA).

B.

The processor needs to notify the controller. And the controller can assess whether there were risks to the data subjects.

C.

The processor needs to notify the controller so that the controller notifies the Supervisory Authority of the personal data breach.

D.

As the error was noticed in time and the report was not sent, there is no need for the processor to inform the controller. The processor must delete the wrong report and generate a new one, this time with the correct data.

Buy Now
Questions 7

The Supervisory Authority is notified whenever an organization intends to process personal data, except for some specific situations. The Supervisory Authority keeps a publicly accessible register of these data processing operations.

What else is a legal obligation of the Supervisory Authority in reaction to such a notification?

Options:

A.

To assess compliance with the law in all classes where sensitive personal data is processed

B.

To assess the legitimacy of operations that involve specific risks for the data subjects

C.

To assess the legitimacy of binding contract(s) between the controller and the data processor(s)

D.

To give out a license for the data processing, specifying the types of personal data which are allowed

Buy Now
Questions 8

What is called the adequacy decision that allows data transfer between the United States and the European Economic Area (EEA)?

Options:

A.

Regulation for transfer of personal data between EEA and USA/

B.

Privacy Shield

C.

General Data Protection Law (GDPL)

D.

General Data Protection Regulation (GDPR)

Buy Now
Questions 9

A person finds that a private videotape showing her in a very intimate situation has been published on a website. She never consented to publication and demands that the video is being removed without undue delay.

According to the GDPR, what should be done next?

Options:

A.

Nothing. The video may be regarded as ‘news’ and, therefore, the website is only exercising its right to freedom of expression and information.

B.

The controller erases the video from the website and, when possible, informs any controller who might

process the same video, that it must be erased.

C.

The controller erases the video from the website. There is no obligation however, to inform others who might have copied it, that it should be erased.

D.

The controller directs the person to seek a lawyer and informs that he cannot exclude before a juridical authorization.

Buy Now
Questions 10

Which of the options below best represents data protection by design?

Options:

A.

It aims to incorporate security measures to protect data from the moment it is collected, throughout the processing and until its destruction at the end of the process

B.

It aims to ensure that personal data is automatically part of a protection process.

C.

It aims to create privacy impact analysis procedures (DPIA), notifications of breaches of privacy and fulfil requests from data subjects.

Buy Now
Questions 11

While paying with a credit card, the card is skimmed (i.e. the data on the magnetic strip is stolen). The magnetic strip contains the account number, expiration date, cardholder’s name and address, PIN number and more.

What kind of a data breach is this?

Options:

A.

Material

B.

Non-material

C.

Verbal

Buy Now
Questions 12

An architect, leaving a building site, puts his laptop for a moment beside his car on the road, while answering his phone. When driving away he sees in the mirror his laptop being crushed by an enormous lorry driving over it. All his files on the design of the building and the calculations he worked on are lost. His only consolation is that those were the only files on the device.

In terms of the GDPR, what happened?

Options:

A.

a data breach

B.

a security incident

C.

a security issue

D.

a vulnerability

Buy Now
Questions 13

What is the main difference between Directive 95/46 / EC and the General Data Protection Regulation (GDPR)?

Options:

A.

The GDPR offers guidance for EU Member States and can create their own laws to comply with the regulation. Directive 95/46 / EC has the force of law and all EU Member States must follow it without changing.

B.

Directive 95/46 / EC offers guidance for EU Member States and can create their own laws to suit the directive. The GDPR has the force of law and all EU Member States must follow it without changing it.

Buy Now
Questions 14

What is the legal status of the GDPR?

Options:

A.

The GDPR is functional law in all member states of the EEA. Some Articles allow for member states law to provide for more specific rules.

B.

The GDPR sets out minimum conditions and requirements. Member states need to pass national laws to meet these minimum requirements.

C.

The GDPR is a recommendation of the European Commission that EEA countries’ law authorities improve their laws on the protection of personal data.

Buy Now
Questions 15

Which of these options is an example of a data breach?

Options:

A.

Transfer of personal data outside the EU

B.

Loss of personal data

C.

A security incident related to corporate data.

Buy Now
Questions 16

What is the main objective of the “Lifecycle Protection” principle?

Options:

A.

All appropriate measures shall be taken to ensure that inaccurate data, taking into account the purposes for which they are processed, are erased or rectified without a delay.

B.

The processing of data must take place in a manner that ensures its security, including protection against unauthorized or unlawful processing and accidental loss, destruction or damage.

C.

Security measures should be in place from the moment data are collected until they are deleted.

D.

Data must be collected for specified, explicit and legitimate purposes and may not be further processed in a manner incompatible with those purposes.

Buy Now
Questions 17

The GDPR refers to the principles of proportionality and subsidiarity. What is the meaning of subsidiarity in this context?

Options:

A.

Personal data may only be processed when there are no other means to achieve the purposes.

B.

Personal data cannot be reused without explicit and informed consent.

C.

Personal data can only be processed in accordance with the purpose specification.

D.

Personal data must be adequate, relevant and not excessive in relation to the purposes.

Buy Now
Questions 18

Who should ask for an opinion after conducting an impact assessment on the protection of personal data (DPIA)?

Options:

A.

DPO

B.

Controller

C.

Supervisory Authority

D.

Processor

Buy Now
Questions 19

How is Data Lifecycle Management (DLM) related to data protection?

Options:

A.

The DLM makes it possible to create a profile of the data subject.

B.

DLM manages the data flow throughout its life cycle.

C.

DLM makes it possible to know the risks and plans how to mitigate them.

Buy Now
Questions 20

Under what EU legislation is data transfer between the EEA and the U.S.A. allowed?

Options:

A.

An adequacy decision based on the Privacy Shield program

B.

An adequacy decision by reason of US domestic legislation

C.

The Transatlantic Trade an Investment Partnership (TTIP)

D.

The U.S.A.’s commitment to join the European Economic Area

Buy Now
Questions 21

To comply with the General Data Protection Regulation (GDPR) it is necessary to create a procedure for reporting data breaches to the Supervisory Authority.

As the controller is a public administration agency, which option is a requirement for this procedure?

Options:

A.

It must contain a step to perform a Data Protection Impact Analysis (DPIA).

B.

It must include an audit step.

C.

It should include a step to consult the Data Protection Officer (DPO) in order to determine whether notification to the Supervisory Authority is necessary.

D.

It must contain a step to notify the data subject.

Buy Now
Questions 22

What is the main reason for performing data protection by design (from conception)?

Options:

A.

Develop technical measures for the protection of personal data.

B.

Enable better marketing campaigns targeted at customers.

C.

Collect as much data as possible for data processing.

D.

Reduce the risk of not meeting legal obligations.

Buy Now
Exam Code: PDPF
Exam Name: Privacy and Data Protection Foundation
Last Update: Nov 23, 2024
Questions: 149

PDF + Testing Engine

$134.99

Testing Engine

$99.99

PDF (Q&A)

$84.99