Labour Day Special - 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: c4sdisc65

PDPF PDF

$38.5

$109.99

3 Months Free Update

  • Printable Format
  • Value of Money
  • 100% Pass Assurance
  • Verified Answers
  • Researched by Industry Experts
  • Based on Real Exams Scenarios
  • 100% Real Questions

PDPF PDF + Testing Engine

$61.6

$175.99

3 Months Free Update

  • Exam Name: Privacy and Data Protection Foundation
  • Last Update: Apr 23, 2024
  • Questions and Answers: 149
  • Free Real Questions Demo
  • Recommended by Industry Experts
  • Best Economical Package
  • Immediate Access

PDPF Engine

$46.2

$131.99

3 Months Free Update

  • Best Testing Engine
  • One Click installation
  • Recommended by Teachers
  • Easy to use
  • 3 Modes of Learning
  • State of Art Technology
  • 100% Real Questions included

PDPF Practice Exam Questions with Answers Privacy and Data Protection Foundation Certification

Question # 6

According to the GDPR, what is a description of binding corporate rules (BCR)?

A.

A decision on the safety of transferring personal data to a non-EEA country

B.

A set of approved rules on personal data protection used by a group of enterprises

C.

A measure to compensate for the lack of personal data protection in a third country

D.

A set of agreements covering personal data transfers between non-EEA countries

Full Access
Question # 7

The Supervisory Authority is notified whenever an organization intends to process personal data, except for some specific situations. The Supervisory Authority keeps a publicly accessible register of these data processing operations.

What else is a legal obligation of the Supervisory Authority in reaction to such a notification?

A.

To assess compliance with the law in all classes where sensitive personal data is processed

B.

To assess the legitimacy of operations that involve specific risks for the data subjects

C.

To assess the legitimacy of binding contract(s) between the controller and the data processor(s)

D.

To give out a license for the data processing, specifying the types of personal data which are allowed

Full Access
Question # 8

According to the GDPR, for which situations should a Data Protection Impact Assessment (DPIA) be conducted?

A.

For all projects that include technologies or processes that require data protection

B.

For all sets of similar processing operations with comparable risks

C.

For any situation where technologies and processes will be subject to a risk assessment

D.

For technologies and processes that are likely to result in a high risk to the rights of data subjects

Full Access
Question # 9

What is the definition of privacy related to the General Data protection Regulation (GDPR)?

A.

A situation in which one is not observed or distributed by the government or uninvited people.

B.

The right to respect for a person’s private and family life, his home and his correspondence.

C.

The fundamental right to respect a person’s physical and mental integrity.

D.

The right to be protected against unsolicited intrusion into a computer or network and the processing of personal data by third parties.

Full Access
Question # 10

According to the GDPR, what is a task of a supervisory authority?

A.

Investigate security breaches of corporate information

B.

Implement technical and organizational measures to ensure compliance

C.

Monitor and enforce the application of the GDPR

Full Access
Question # 11

What is the definition of Supervisory Authority according to the GDPR?

A.

Individual or legal entity processing personal data on behalf of the person responsible for processing personal data.

B.

An independent public authority created by a Member State.

C.

Individual or legal entity that is not authorized to process personal data

D.

Individual or legal entity that, individually or in conjunction with others, determines the purposes and means of processing personal data.

Full Access
Question # 12

A controller can contract out the processing of personal data to another company, provided a written contract between these partners is in place.

Which clause in this contract is a responsibility of the controller?

A.

To ensure that persons authorized to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

B.

To make available all information necessary to demonstrate compliance with the obligations laid down in the GDPR and allow for and contribute to audits, including inspections.

C.

To process the personal data only on documented instructions, including with regard to transfers of personal data to a third country or an international organization.

D.

To provide sufficient guarantees for appropriate technical and organizational measures in such a manner that processing will meet the requirements of the GDPR.

Full Access
Question # 13

Which data subject right is explicitly defined by the GDPR?

A.

A copy of personal data must be provided in the format requested by the data subject.

B.

Personal data must always be erased if the data subject requests this.

C.

Access to personal data must be provided free of charge for the data subject.

D.

Personal data must always be changed at the request of the data subject.

Full Access
Question # 14

Regarding the Portability Law for data subjects, which option is correct?

A.

The data subject has the right to object at any time, for reasons related to their particular situation, so that the data is not shared between controllers.

B.

The data subject has the right to ask the controller to rectify, erase or limit the processing of personal data with respect to the data subject if he has shared his data.

C.

The data owner has the right to transmit his data to another controller without the controller that already has the personal data provided being able to prevent it.

D.

The data subject has the right to obtain from the controller the limitation of processing so that the data is shared.

Full Access
Question # 15

According to the GDPR, what is a mandatory topic in a DPIA report?

A.

Systematic description of the fiduciary duties to ensure compliance to all relevant laws and regulations

B.

An assessment of the necessity and proportionality of the processing operations in relation to the purposes

C.

The documentation of the risks to the rights and freedoms of the data protection officer

D.

The measures envisaged to address the privacy compliance frameworks risks

Full Access
Question # 16

How does a Supervisory Authority collaborate to the application of GDPR?

A.

Assists in the implementation of a data protection management system (at controller request).

B.

Monitor and enforce the application of this Regulation.

C.

Perform a Data Privacy Impact Analysis (DPI) at the request of the Data Protection Officer – DPO.

D.

Determines technical safety measures to be applied to the controller.

Full Access
Question # 17

An architect, leaving a building site, puts his laptop for a moment beside his car on the road, while answering his phone. When driving away he sees in the mirror his laptop being crushed by an enormous lorry driving over it. All his files on the design of the building and the calculations he worked on are lost. His only consolation is that those were the only files on the device.

In terms of the GDPR, what happened?

A.

a data breach

B.

a security incident

C.

a security issue

D.

a vulnerability

Full Access
Question # 18

An Independent Supervisory Authority has several responsibilities. Which of the following is one of these?

A.

Supervise the application of the General Data Protection Regulation (GDPR).

B.

Assist in the elaboration and adaptation of the specific data protection laws of each country.

C.

Conduct a Data Protection Impact Assessment (DPIA).

D.

Assist in the planning of a Personal Data Protection Management System when requested by the Controller.

Full Access
Question # 19

What is called the adequacy decision that allows data transfer between the United States and the European Economic Area (EEA)?

A.

Regulation for transfer of personal data between EEA and USA/

B.

Privacy Shield

C.

General Data Protection Law (GDPL)

D.

General Data Protection Regulation (GDPR)

Full Access
Question # 20

While paying with a credit card, the card is skimmed (i.e. the data on the magnetic strip is stolen). The magnetic strip contains the account number, expiration date, cardholder’s name and address, PIN number and more.

What kind of a data breach is this?

A.

Material

B.

Non-material

C.

Verbal

Full Access
Question # 21

While performing a backup, a data server disk crashed. Both the data and the backup are lost. The disk contained personal data, but no special category personal data. The processor states that this is a personal data breach. Is the statement of the processor true?

A.

Yes, because there were no special category personal data stored on the disk.

B.

No, because no personal data on the disk were processed, only destroyed

C.

Yes, because the personal data on the disk were unlawfully processed.

D.

No, because this is only a security incident and not a data breach

Full Access
Question # 22

Which of the alternatives describes one of the Supervisory Authority’s responsibilities?

A.

Supervise the processing of data of holders residing in a country belonging to the European Economic Area (EEA).

B.

Consider the nature of the treatment, and as far as possible, assist the controller in order to enable the controller to fulfill his obligation.

C.

Provide the controller with all necessary information to demonstrate compliance with obligations.

D.

Apply technical and organizational measures to ensure that only personal data that are necessary for each specific purpose of processing are processed.

Full Access