Leads4pass > EXIN > Privacy & Data Protection > PDPF > PDPF Online Practice Questions and Answers

PDPF Online Practice Questions and Answers

Questions 4

The General Data Protection Regulation (GDPR) formalizes the data subject's right to data portability.

What is the objective of data portability?

A. The controller has the right to move the data subject's personal data from one organization to another.

B. The data subject has the right to move personal data concerning him or her.

C. The data subject has the right to move his/her personal data when moving to another country.

D. The Supervisory Authority authorizes the movement of personal data.

Buy Now
Questions 5

Personal data can be transferred outside of the EEA. According to the GDPR, which transfers outside the EEA are always lawful?

A. Transfers based on the laws of the non-EEA country concerns

B. Transfers falling under World Trade Organization rules

C. Transfers governed by approved binding corporate rules (BCR)

D. Transfers within a global corporation or organization

Buy Now
Questions 6

After appearing in a photo posted by a friend on a social network, a person felt embarrassed and decided that he wants the photo to be deleted.

According to the General Data Protection Regulation (GDPR), does that person have the right to delete this photo?

A. False

B. True

Buy Now
Questions 7

Which of the following conflicts with the principle of limiting the purposes?

A. The data is sold to another company without the consent of the data subject.

B. Adapt the data to the purpose of the treatment.

C. Store the data in a way that allows the identification of the data subjects.

D. Data is used in an obscure manner to the data subject.

Buy Now
Questions 8

The Control Authority may impose fines on organizations that are not meeting the mandatory requirements of the General Data Protection Regulation (GDPR).

A. False

B. True

Buy Now
Questions 9

The word privacy is never mentioned in the General Data Protection Regulation (GDPR) text.

Despite this, what would be the best definition of the privacy according to the Regulation?

A. The right not to have your life monitored by technologies.

B. Have freedom of expression.

C. The right to respect for private and family life, for home and communications.

D. The right to have your personal data protected.

Buy Now
Questions 10

An Independent Supervisory Authority has several responsibilities. Which of the following is one of these?

A. Supervise the application of the General Data Protection Regulation (GDPR).

B. Assist in the elaboration and adaptation of the specific data protection laws of each country.

C. Conduct a Data Protection Impact Assessment (DPIA).

D. Assist in the planning of a Personal Data Protection Management System when requested by the Controller.

Buy Now
Questions 11

A controller asks a processor to produce a report containing customers who have purchased a particular product more than once in the past 6 months.

The processor provides services to several companies (which in this case are the controllers).

When generating the requested report, it uses customer data collected by another controller, that is, for a different purpose.

Fortunately, the error is noticed in time, the report is not sent, and nobody has had access to this data.

In this case, how does the processor need to proceed and what action should the controller take?

A. The processor notifies the Supervisory Authority that a violation has occurred. The controller will be notified and must perform a Data Protection Impact Assessment (DPIA).

B. The processor needs to notify the controller. And the controller can assess whether there were risks to the data subjects.

C. The processor needs to notify the controller so that the controller notifies the Supervisory Authority of the personal data breach.

D. As the error was noticed in time and the report was not sent, there is no need for the processor to inform the controller. The processor must delete the wrong report and generate a new one, this time with the correct data.

Buy Now
Questions 12

A person who works for a union took home a draft newsletter to finish it. The thumb drive containing the draft and contact list has been lost. To whom, among others, this data breach should be reported?

A. To all members of the contact list

B. To the Union staff

C. To the police

Buy Now
Questions 13

According to the GDPR, in what situation must data subjects always be notified of a personal data breach?

A. When personal data is processed at a facility of the processor that is not located within the borders of the EEA

B. When personal data is processed by a party that agreed to the draft processing contract but has not yet signed it

C. When the system on which the personal data is processed is attacked causing damage to its storage devices

D. When there is a significant probability that the breach will lead to a high risk for the privacy of the data subjects

Buy Now
Exam Code: PDPF
Exam Name: Privacy and Data Protection Foundation
Last Update: Jan 18, 2025
Questions: 149
10%OFF Coupon Code: SAVE10

PDF (Q&A)

$49.99

VCE

$55.99

PDF + VCE

$65.99