Halloween Special - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: sntaclus

Which of the following conflicts with the principle of limiting the purposes?

A.

The data is sold to another company without the consent of the data subject.

B.

Adapt the data to the purpose of the treatment.

C.

Store the data in a way that allows the identification of the data subjects.

D.

Data is used in an obscure manner to the data subject.

In its Article 9 the GDPR categorizes some types of personal data as “sensitive”.

Of these below which are considered sensitive?

A.

Date of birth of a person.

B.

A person’s home address.

C.

Soccer team that a person supports.

D.

Result of a medical examination.

What is a responsibility of Supervisory Authorities in EEA countries?

A.

Research on security breaches of corporate information

B.

Supervision of all data processing operations controlled by a controller in an EEA country

C.

Supervision of all data processing operations where the data subjects are residents of an EEA country

Personal data shall be adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed. Which data processing principle is described here?

A.

Purpose limitation

B.

Data minimization

C.

Accuracy

D.

Fairness and transparency

Racial or ethnic origin, political opinions, religious or philosophical beliefs, or union membership, as well as the processing of genetic data, biometric data, health data or data relating to a person’s sexual life or sexual orientation.

What does this sentence above refer to?

A.

Available personal data categories.

B.

Rights categories of data subjects.

C.

Categories of purposes for the processing of personal data.

D.

Personal data categories.

The General Data Protection Regulation (GDPR) formalizes the data subject’s right to data portability.

What is the objective of data portability?

A.

The controller has the right to move the data subject’s personal data from one organization to another.

B.

The data subject has the right to move personal data concerning him or her.

C.

The data subject has the right to move his/her personal data when moving to another country.

D.

The Supervisory Authority authorizes the movement of personal data.

What is the purpose of a data protection audit by the supervisory authority?

A.

To monitor and enforce the application of the GDPR by assessing that processing is performed in compliance with the GDPR.

B.

To fulfill the obligation in the GDPR to implement appropriate technical and organizational measures for data protection.

C.

To advise the controller on the mitigation of privacy risks to protect the controller from liability claims for

non-compliance.

The Traffic Department of a city wants to know how many cars travel daily in order to plan the number of spaces needed to implement a rotating parking system.

To do this, cameras were installed at strategic points. Through image recognition software it is possible to capture the license plate and know how many cars traveled in the city. A monthly report is issued with the average number of cars present each day.

Signs and posters were spread around the city informing drivers and citizens what is the purpose of processing and that the data will be stored for up to five years, for future comparison.

What basic principle of legitimate processing of personal data is being violated in this case?

A.

Personal data must be kept in a way that allows the identification of data subjects for a period not longer than necessary.

B.

Personal data must be processed transparently in relation to the data subject.

C.

Personal data must be processed in a way that guarantees the appropriate security of personal data.

D.

Personal data must be collected for specific, explicit and legitimate purposes and must not be further processed for incompatible purposes.

What is the term used in the General Data Protection Regulation (GDPR) for the disclosure of, or unauthorized access to, personal data?

A.

Security incident

B.

Incident

C.

Breach of confidentiality

D.

Data breach

A controller wants to outsource processing of personal data to a processor. What must be done before outsourcing?

A.

The processor must show the controller that all demands agreed in the service level agreement (SLA) are met.

B.

The controller and processor must draft and sign a written contract guaranteeing the confidentiality of the data.

C.

The controller must ask the supervisory authority for permission to outsource the processing of the data.

D.

The controller must ask the supervisory authority if the agreed written contract is compliant with the regulations.