Summer Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: ecus65

Exin PDPF - Privacy and Data Protection Foundation

Page: 4 / 5
Total 149 questions

According to the GDPR, what is a description of binding corporate rules (BCR)?

A.

A decision on the safety of transferring personal data to a non-EEA country

B.

A set of approved rules on personal data protection used by a group of enterprises

C.

A measure to compensate for the lack of personal data protection in a third country

D.

A set of agreements covering personal data transfers between non-EEA countries

A person buys a product at a store located in the European Economic Area (EEA). At the time of purchase, you are asked to fill out a registration form and he informs his personal email.

As is usual in many stores, in the next few days this person will start receiving several marketing emails. He considers the frequency of these emails to be very high. Demanding his rights, he asks the store to delete all his personal data.

What the store must do according to the General Data Protection Regulation (GDPR)?

A.

The owner does not have this right, since he bought a product in the store, he has the right to send emails with new promotions.

B.

The store has 30 days from the date of receipt of the customer’s request to delete all data at no cost to the customer.

C.

The store must delete customer data from its advertising list. Purchase data cannot be deleted, as financial data has to be kept longer.

What is the most important difference between the 95/46/EC and the GDPR?

A.

95/46/EC applies as law in all EEA member states while the GDPR is a guidance.

B.

95/46/EC applies to processing of data on EEA residents worldwide and the GDPR does not.

C.

The GDPR applies as law in all EEA member states while 95/46/EC is a guidance.

D.

The GDPR applies to persons and organizations which process personal data within EEA member states.

The scope of 95/46/EC is more restricted in this aspect.

While paying with a credit card, the card is skimmed (i.e. the data on the magnetic strip is stolen). The magnetic strip contains the account number, expiration date, cardholder’s name and address, PIN number and more.

What kind of a data breach is this?

A.

Material

B.

Non-material

C.

Verbal

GDPR quotes in one of its principles that personal data should be adequate, relevant and limited to what is necessary in relation to its purpose. What principle is this?

A.

integrity and confidentiality

B.

purpose limitation

C.

data minimization

D.

lawfulness, loyalty and transparency

According to the GDPR, what is a task of a supervisory authority?

A.

Investigate security breaches of corporate information

B.

Implement technical and organizational measures to ensure compliance

C.

Monitor and enforce the application of the GDPR

A controller wants to switch processors. What is necessary to review before making this change, so that it remains GDPR compliant?

A.

The matrix location of this new processor.

B.

Require the old processor to erase data.

C.

Require the old processor to port the data.

D.

Verify that the new processor has sufficient security guarantees.

The Traffic Department of a city wants to know how many cars travel daily in order to plan the number of spaces needed to implement a rotating parking system.

To do this, cameras were installed at strategic points. Through image recognition software it is possible to capture the license plate and know how many cars traveled in the city. A monthly report is issued with the average number of cars present each day.

Signs and posters were spread around the city informing drivers and citizens what is the purpose of processing and that the data will be stored for up to five years, for future comparison.

What basic principle of legitimate processing of personal data is being violated in this case?

A.

Personal data must be kept in a way that allows the identification of data subjects for a period not longer than necessary.

B.

Personal data must be processed transparently in relation to the data subject.

C.

Personal data must be processed in a way that guarantees the appropriate security of personal data.

D.

Personal data must be collected for specific, explicit and legitimate purposes and must not be further processed for incompatible purposes.

What is the purpose of Data Lifecycle Management (DLM)?

A.

Ensure data integrity and its periodic update

B.

Ensure data confidentiality and availability throughout its useful life.

C.

Ensure that the processing of personal data, throughout its useful life complies with the GDPR

D.

Ensure data confidentiality throughout its useful life, from collection to deletion.

A gentleman has a loan denied by the bank’s system that he has been a customer for many years. He is disgusted, because the loan would make it possible to hold the wedding of his only granddaughter.

He contacts the bank and asks for explanations. He wants to know exactly why his loan was denied and based on what information.

What right is required by the data subject according to the GDPR?

A.

Right to limitation of treatment

B.

Right to rectification

C.

Data subject’s right of access

D.

Right to object and automated individual decision-making