Exin PDPF - Privacy and Data Protection Foundation
According to the GDPR, what is a description of binding corporate rules (BCR)?
A person buys a product at a store located in the European Economic Area (EEA). At the time of purchase, you are asked to fill out a registration form and he informs his personal email.
As is usual in many stores, in the next few days this person will start receiving several marketing emails. He considers the frequency of these emails to be very high. Demanding his rights, he asks the store to delete all his personal data.
What the store must do according to the General Data Protection Regulation (GDPR)?
What is the most important difference between the 95/46/EC and the GDPR?
While paying with a credit card, the card is skimmed (i.e. the data on the magnetic strip is stolen). The magnetic strip contains the account number, expiration date, cardholder’s name and address, PIN number and more.
What kind of a data breach is this?
GDPR quotes in one of its principles that personal data should be adequate, relevant and limited to what is necessary in relation to its purpose. What principle is this?
According to the GDPR, what is a task of a supervisory authority?
A controller wants to switch processors. What is necessary to review before making this change, so that it remains GDPR compliant?
The Traffic Department of a city wants to know how many cars travel daily in order to plan the number of spaces needed to implement a rotating parking system.
To do this, cameras were installed at strategic points. Through image recognition software it is possible to capture the license plate and know how many cars traveled in the city. A monthly report is issued with the average number of cars present each day.
Signs and posters were spread around the city informing drivers and citizens what is the purpose of processing and that the data will be stored for up to five years, for future comparison.
What basic principle of legitimate processing of personal data is being violated in this case?
What is the purpose of Data Lifecycle Management (DLM)?
A gentleman has a loan denied by the bank’s system that he has been a customer for many years. He is disgusted, because the loan would make it possible to hold the wedding of his only granddaughter.
He contacts the bank and asks for explanations. He wants to know exactly why his loan was denied and based on what information.
What right is required by the data subject according to the GDPR?