Halloween Special - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: sntaclus

We know that when browsing the internet there is a lot of personal data that is collected. One mechanism for collecting this data is cookies.

How do marketers use this collected personal data?

A.

Collecting logs from web servers and running campaigns promoting products on social media.

B.

Collecting the logs from the web servers, they analyze which products are most visited and sold, promoting marketing campaigns for these products.

C.

They create behavioral profiles, applying tags to web page visitors. These profiles can be marketed and used in targeted marketing campaigns.

After notifying the supervisory authority, what should be the first action the controller must take when it finds a security breach where unauthorized people have accessed personal data?

A.

Contact the DPO for formal notification to the Supervisory Authority.

B.

Analyze whether sensitive data has been accessed.

C.

Register a Police Report at the cybercrime station.

D.

Notify data subjects that have been subject to a security breach.

What is the essence of the principle ‘Full Lifecycle Protection’?

A.

Delivering the maximum degree of data protection by default, ensuring that personal data are automatically protected in any given IT system or business practice.

B.

Ensuring that whatever business practice or technology is involved, processing is done according to the stated objectives, subject to independent verification.

C.

Embedding security measures to protect the data from the moment it is collected, throughout processing until it is destroyed at the end of the process.

D.

Prioritizing the protection of the interests of the individual by offering for example strong privacy defaults, appropriate notice or empowering user-friendly options.

One of the objectives of a data protection impact assessment (DPIA) is to strengthen the confidence of customers or citizens in the way personal data is processed and privacy is respected. How can a DPIA strengthen the confidence?

A.

The organization proves that it takes privacy seriously and aims for compliance with the GDPR.

B.

The organization minimizes the risk of costly adjustments in processes or the redesign of systems in a later stage.

C.

The organization prevents non-compliance with the GDPR and minimizes the risk of fines

Which cause is a data breach according to the GDPR?

A.

illegally obtained corporate data from a human resources management system

B.

Personal data is processed without a binding contract.

C.

Personal data is processed by anyone other than the controller, processor or, possibly, subprocessor

D.

The operation of a vulnerable server in the internal network of the processor

Which EU legislation allows data to be transferred between the European Economic Area (EEA) and the United States (USA)?

A.

A suitability decision based on the Privacy Shield program

B.

A transfer made on the basis of World Trade Organization legislation.

C.

European Union Directive 95/46 / EC.

D.

A transfer made under UN law.

What is the main use of a persistent cookie?

A.

To save the pages a user has bookmarked in the user’s browser history

B.

To record every keystroke made by a computer user to find out passwords

C.

To ensure that the user’s personal data are stored securely on the server

D.

To personalize the user’s experience of the website during the next visit

A breach of security that leads to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored or otherwise processed. What is the exact term that is associated with this definition in the GDPR?

A.

Security breach

B.

Personal data breach

C.

Confidentiality violation

D.

Security incident

A company wishes to use personal data of their customers. They wish to start sending all female customers a customized newsletter. What right do all data subjects have in this scenario?

A.

The right to rectification

B.

The right to compensation

C.

The right to object to profiling

What is the legal status of the GDPR?

A.

The GDPR is functional law in all member states of the EEA. Some Articles allow for member states law to provide for more specific rules.

B.

The GDPR sets out minimum conditions and requirements. Member states need to pass national laws to meet these minimum requirements.

C.

The GDPR is a recommendation of the European Commission that EEA countries’ law authorities improve their laws on the protection of personal data.