Weekend Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: xmas50

Exin PDPF - Privacy and Data Protection Foundation

Page: 1 / 5
Total 149 questions

An Independent Supervisory Authority has several responsibilities. Which of the following is one of these?

A.

Supervise the application of the General Data Protection Regulation (GDPR).

B.

Assist in the elaboration and adaptation of the specific data protection laws of each country.

C.

Conduct a Data Protection Impact Assessment (DPIA).

D.

Assist in the planning of a Personal Data Protection Management System when requested by the Controller.

According to the General Data Protection Regulation (GDPR), which category of personal data is considered to be sensitive data?

A.

Labor union association

B.

Passport number

C.

Credit card details

D.

Social security number

We know that when a personal data breach occurs, the data controller (Controller) must notify the Supervisory Authority within 72 hours, without justified delay. However, should the Controller do if it is unable to communicate within this time?

A.

Send the notification with the date of the violation changed, to remain within 72 hours.

B.

After 72 hours there is no longer any need to send notification of personal data breach.

C.

Do not notify and seek ways to hide the violation so that the Supervisory Authority or the titleholders are made aware

D.

Send the notification, even after 72 hours, accompanied by the reasons for the delay

The GDPR refers to the principles of proportionality and subsidiarity. What is the meaning of subsidiarity in this context?

A.

Personal data may only be processed when there are no other means to achieve the purposes.

B.

Personal data cannot be reused without explicit and informed consent.

C.

Personal data can only be processed in accordance with the purpose specification.

D.

Personal data must be adequate, relevant and not excessive in relation to the purposes.

A shopkeeper wants to register how many visitors enter his shop every day. A system detects the MAC- address of each visitor’s smartphone. It is impossible for the shopkeeper to identify the owner of the phone from this signal, but telephone providers can link the MAC-address to the owner of the phone. According to the GDPR, is the shopkeeper allowed to use this method?

A.

Yes, because the shopkeeper cannot identify the owner of the telephone

B.

No, because the telephone providers are the owners of the MAC-addresses.

C.

No, because the telephone’s MAC-address must be regarded as personal data.

D.

Yes, because the visitor has automatically consented by connecting to the Wi-Fi

To plan the amount of parking space needed, a local government monitors and saves the license plate number of every car that enters and leaves the city center. They have obtained permission to collect data on the number of cars present in the city center. By comparing the license plate time of entry and exit the number of cars present every moment of each day is calculated. Each month a report is created detailing the average number of cars in the city center at specific moments for every day of the week. At every entrance to the city center, a billboard clearly states what data is collected by whom, the purpose of the processing and the fact that the license plate numbers are saved securely for up to two years, because the measurements will be repeated next year. Which of the basic principles for legitimate processing of personal data is violated in this scenario?

A.

Personal data are processed in a manner that ensures appropriate security of the personal data.

B.

Personal data are processed in a transparent manner in relation to the data subject

C.

Personal data are kept in a form permitting identification of data subjects for no longer than is necessary.

D.

Personal data are collected for specified, explicit and legitimate purposes and not further processed.

A natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data. Which role in data protection is defined here?

A.

Third party

B.

Processor

C.

Controller

D.

Supervisory authority

According to the GDPR, for which situations should a Data Protection Impact Assessment (DPIA) be conducted?

A.

For all projects that include technologies or processes that require data protection

B.

For all sets of similar processing operations with comparable risks

C.

For any situation where technologies and processes will be subject to a risk assessment

D.

For technologies and processes that are likely to result in a high risk to the rights of data subjects

What is the role of the one assigned the responsibility to govern the purposes and means of processing personal data within an organization, according to the GDPR?

A.

Controller

B.

Data Protection Officer

C.

Data Subject

D.

Processor

In the European Union we have: Directives and Regulations. What is the difference between them?

A.

The regulation provides guidance for EU Member States and they can create their own laws to conform to the regulation. A directive has the force of law and all EU Member States must follow it without changing it.

B.

The directive provides guidance for EU member states and they can create their own laws to suit the directive. A regulation has the force of law and all EU Member States must follow it without changing it.