Summer Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: ecus65

Exin PDPF - Privacy and Data Protection Foundation

Page: 3 / 5
Total 149 questions

How does GDPR regulate this specific case?

A woman uses the services of a gym in the city where she lives. Yet she will move to another town. So, she requests the current gym to transfer all her data, exercises, eating plans, physical evaluations, etc. to another gym in the new town.

A.

The current gym is not obliged to answer the holder request, because this could jeopardize the secret of its business.

B.

The current gym should send all her data directly to the new gym.

C.

The gym of the new town should get in contact with the gym and request the data.

D.

The current gym should provide the data to her.

The word privacy is never mentioned in the General Data Protection Regulation (GDPR) text.

Despite this, what would be the best definition of the privacy according to the Regulation?

A.

The right not to have your life monitored by technologies.

B.

Have freedom of expression.

C.

The right to respect for private and family life, for home and communications.

D.

The right to have your personal data protected.

In the contract between the controller and processor for the processing of personal data, which of the options below represents the sole responsibility of the Controller?

A.

Erase all personal data after the completion of treatment-related services, deleting existing copies.

B.

Treat personal data only through documented instructions, including with regard to data transfers to third countries or international organizations.

C.

Ensure that the persons authorized to process personal data have made a commitment to confidentiality.

D.

Apply technical and organizational measures to ensure that only personal data that are necessary for each specific purpose of processing are processed.

While performing a backup, a data server disk crashed. Both the data and the backup are lost. The disk contained personal data, but no special category personal data. The processor states that this is a personal data breach. Is the statement of the processor true?

A.

Yes, because there were no special category personal data stored on the disk.

B.

No, because no personal data on the disk were processed, only destroyed

C.

Yes, because the personal data on the disk were unlawfully processed.

D.

No, because this is only a security incident and not a data breach

The Control Authority may impose fines on organizations that are not meeting the mandatory requirements of the General Data Protection Regulation (GDPR).

A.

False

B.

True

A controller discovers that a data subject, who had given consent for the processing of his data, has passed away. What this implies for data processing according to the General Data Protection Regulation (GDPR)?

A.

With the death of the data owner, the controller can continue processing the data, as they are no longer under the GDPR.

B.

The data can only be processed by the controller respecting the consent provided by the holder.

C.

The controller must delete the data of the holder, since with the death of the holder the consent is automatically revoked.

D.

The controller can process the data of a deceased person as long as it anonymizes the data.

A controller wants to outsource processing of personal data to a processor. What must be done before outsourcing?

A.

The processor must show the controller that all demands agreed in the service level agreement (SLA) are met.

B.

The controller and processor must draft and sign a written contract guaranteeing the confidentiality of the data.

C.

The controller must ask the supervisory authority for permission to outsource the processing of the data.

D.

The controller must ask the supervisory authority if the agreed written contract is compliant with the regulations.

In what way are online activities of people most effectively used by modern marketers?

A.

By analyzing the logs of the web server it can be seen which products are top sellers, allowing them to optimize their marketing campaigns for those products.

B.

By tagging users of social media, profiles of their online behavior can be created. These profiles are used to ask them to promote a product.

C.

By tagging visitors of web pages, profiles of their online behavior can be created. These profiles are sold and used in targeted advertisement campaigns.

According to Article.33 of the GDPR the controller shall without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach to the supervisory authority. What is the maximum penalty for non-compliance with this notification obligation?

A.

€ 10.000.000 or 2% of the annual global turnover, whichever is higher

B.

€ 20.000.000 or 4% of the annual global turnover, whichever is higher

C.

Up to € 500.000 with a minimum of € 120.000

D.

Up to € 820.000 with a minimum of € 350.000

What is a responsibility of Supervisory Authorities in EEA countries?

A.

Research on security breaches of corporate information

B.

Supervision of all data processing operations controlled by a controller in an EEA country

C.

Supervision of all data processing operations where the data subjects are residents of an EEA country