What is the role of the one assigned the responsibility to govern the purposes and means of processing personal data within an organization, according to the GDPR?
A. Controller
B. Data Protection Officer
C. Data Subject
D. Processor
The GDPR states that records of processing activities must be kept by the controller. To whom must the controller make these records available, if requested?
A. The data processor
B. The Data Protection Officer
C. The European Commission
D. The supervisory authority
Which situation is considered a data breach according to the GDPR?
A. A processor deletes personal data after his contract with the controller expired.
B. A processor leaves his computer unattended, where colleagues may be able to access it.
C. After a disk crash a processor restores personal data from a recent back-up.
D. After processing a processor deletes personal data on instruction of the controller.
Data protection and privacy are closely related terms. Which of these options best represent this relationship?
A. Privacy is a part of data protection that aims to keep personal data confidential.
B. Data protection is a part of privacy that aims to keep personal data confidential.
C. The two terms have the same meaning. They are synonymous.
D. Without protection of personal data there is no privacy.
The Control Authority may impose fines on organizations that are not meeting the mandatory requirements of the General Data Protection Regulation (GDPR).
A. False
B. True
Subcontracting treatment is regulated by contract or other regulatory act under Union or Member State law, which links the processor to the controller.
What this contract or other regulatory act stipulates?
A. A process for testing, assessing and regularly evaluating the effectiveness of technical and organizational measures to ensure safe treatment.
B. The processor assists the driver through technical and organizational measures to enable it to fulfill its obligation to respond to requests from data subjects.
C. The description of categories of data subjects and categories of personal data
D. The purpose of data processing
Which of these should appear in a Data Protection Impact Assessment (DPIA) according to the General Data Protection Regulation (GDPR)?
A. An assessment of the need and proportionality of treatment operations in relation to the objectives.
B. Data Protection Officer (DPO) contact and responsibilities.
C. An inventory and the flow of personal data within the organization.
D. A survey of other laws that must be taken into account in addition to the GDPR.
According to the General Data Protection Regulation (GDPR), which category of personal data is considered to be sensitive data?
A. Labor union association
B. Passport number
C. Credit card details
D. Social security number
To plan the amount of parking space needed, a local government monitors and saves the license plate number of every car that enters and leaves the city center. They have obtained permission to collect data on the number of cars present in the city center. By comparing the license plate time of entry and exit the number of cars present every moment of each day is calculated. Each month a report is created detailing the average number of cars in the city center at specific moments for every day of the week. At every entrance to the city center, a billboard clearly states what data is collected by whom, the purpose of the processing and the fact that the license plate numbers are saved securely for up to two years, because the measurements will be repeated next year. Which of the basic principles for legitimate processing of personal data is violated in this scenario?
A. Personal data are processed in a manner that ensures appropriate security of the personal data.
B. Personal data are processed in a transparent manner in relation to the data subject
C. Personal data are kept in a form permitting identification of data subjects for no longer than is necessary.
D. Personal data are collected for specified, explicit and legitimate purposes and not further processed.
A security breach has occurred in an information system that also holds personal data. According to the GDPR, what is the very first thing the controller must do?
A. Assess the risk of adverse effects to the data subjects using a data protection impact assessment (DPIA)
B. Ascertain whether the breach may have resulted in loss or unlawful processing of personal data
C. Report the breach immediately to all data subjects and the relevant supervisory authority
D. Assess whether personal data of a sensitive nature has or may have been unlawfully processed