3 Months Free Update
3 Months Free Update
3 Months Free Update
Which of the following conflicts with the principle of limiting the purposes?
Racial or ethnic origin, political opinions, religious or philosophical beliefs, or union membership, as well as the processing of genetic data, biometric data, health data or data relating to a person’s sexual life or sexual orientation.
What does this sentence above refer to?
A controller wants to switch processors. What is necessary to review before making this change, so that it remains GDPR compliant?
The General Data Protection Regulation (GDPR) is based on the principles of proportionality and subsidiarity.
What is the meaning of “proportionality” in this context?
The General Data Protection Regulation (GDPR) came into effect on May 25, 2018, what is the legal status of this regulation?
Who should ask for an opinion after conducting an impact assessment on the protection of personal data (DPIA)?
A personal data breach has occurred, and the controller is writing a draft notification for the supervisory authority. The following information is already in the notification:
-The nature of the personal data breach and its possible consequences.
-Information regarding the parties that can provide additional information about the data breach.
What other information must the controller provide?
When a data breach occurs in a company that has branches in several countries of the European Union, which supervisory authority is competent to take the appropriate measures?
In the European Union we have: Directives and Regulations. What is the difference between them?
What is the main difference between Directive 95/46 / EC and the General Data Protection Regulation (GDPR)?
While paying with a credit card, the card is skimmed (i.e. the data on the magnetic strip is stolen). The magnetic strip contains the account number, expiration date, cardholder’s name and address, PIN number and more.
What kind of a data breach is this?
The GDPR does not define privacy as a term but uses the concept implicitly throughout the text. What is a correct definition of privacy as implicitly used throughout the GDPR?
What is the main reason for performing data protection by design (from conception)?
A Belgian company has their headquarters in France for tax purposes. They enter into a legally binding contract with a processor in the Netherlands for the processing of personal data of data subjects with various nationalities. A personal data breach occurs. The supervisory authorities start an investigation. Why is the French supervisory authority seen as the lead supervisory authority?
Which of the following has a data breach under the General Data Protection Regulation (GDPR)?
When personal data are processed, who is ultimately responsible for demonstrating compliance with the GDPR?
A company’s director’s notebook is accidentally wet, which permanently damages the equipment so that it cannot recover its data.
The lost data concerned the financial reports of the company. What happened in this case according to GDPR?
According to the principle of purpose limitation, data should not be processed beyond the legitimate purpose defined. However, further processing is allowed in a few specific cases, provided that appropriate safeguards for the rights and freedoms of the data subjects are taken. For which purpose is further processing not allowed?
The Supervisory Authority is notified whenever an organization intends to process personal data, except for some specific situations. The Supervisory Authority keeps a publicly accessible register of these data processing operations.
What else is a legal obligation of the Supervisory Authority in reaction to such a notification?
One of the seven principles of data protection by design is Functionality - Positive-Sum, not Zero-Sum. What is the essence of this principle?
In the GDPR, some types of personal data are regarded as special category personal data. Which personal data are considered special category personal data?
According to the GDPR, in what situation must data subjects always be notified of a personal data breach?
Someone regularly receives offers from a store where he purchased something five years ago. He wants the company to stop sending offers and to wipe his personal data.
Which aspect of the rights of a data subject in the General Data Protection Regulation (GDPR) requires the company to comply?
The GDPR contains several items. Which of these contains mandatory requirements?
Organizations are obliged to keep a number of records to demonstrate compliance with the GDPR. Which record is not obligatory according to the GDPR?
A controller asks a processor to produce a report containing customers who have purchased a particular product more than once in the past 6 months.
The processor provides services to several companies (which in this case are the controllers).
When generating the requested report, it uses customer data collected by another controller, that is, for a different purpose.
Fortunately, the error is noticed in time, the report is not sent, and nobody has had access to this data. In this case, how does the processor need to proceed and what action should the controller take?
The GDPR states that records of processing activities must be kept by the controller. To whom must the controller make these records available, if requested?
Some data processing falls outside of the material scope of the GDPR. What type of processing is not subject to the GDPR?
Who is responsible for demonstrating the compliance of personal data processing with the General Data Protection Regulation (GDPR)?
The GDPR refers to the principles of proportionality and subsidiarity. What is the meaning of subsidiarity in this context?
The Control Authority may impose fines on organizations that are not meeting the mandatory requirements of the General Data Protection Regulation (GDPR).
A person finds that a private videotape showing her in a very intimate situation has been published on a website. She never consented to publication and demands that the video is being removed without undue delay.
According to the GDPR, what should be done next?