Halloween Special - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: sntaclus

In what way are online activities of people most effectively used by modern marketers?

A.

By analyzing the logs of the web server it can be seen which products are top sellers, allowing them to optimize their marketing campaigns for those products.

B.

By tagging users of social media, profiles of their online behavior can be created. These profiles are used to ask them to promote a product.

C.

By tagging visitors of web pages, profiles of their online behavior can be created. These profiles are sold and used in targeted advertisement campaigns.

How should data protection between the processor and controller be regulated in accordance with the General Data Protection Regulation (GDPR)?

A.

Contract

B.

Supervisory Authority endorsement.

C.

Compulsory Corporate Rules.

D.

Standard contractual clauses.

When does the GDPR require data subjects consent to a cookie?

A.

Always, because a cookie is regarded as online identifier

B.

Never, as the EU Cookie Law does not require explicit consent

C.

Only if the cookie contains authentication information of the data subject

D.

Only if the cookie contains shopping basket items

To comply with the General Data Protection Regulation (GDPR) it is necessary to create a procedure for reporting data breaches to the Supervisory Authority.

As the controller is a public administration agency, which option is a requirement for this procedure?

A.

It must contain a step to perform a Data Protection Impact Analysis (DPIA).

B.

It must include an audit step.

C.

It should include a step to consult the Data Protection Officer (DPO) in order to determine whether notification to the Supervisory Authority is necessary.

D.

It must contain a step to notify the data subject.

A natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data. Which role in data protection is defined here?

A.

Third party

B.

Processor

C.

Controller

D.

Supervisory authority

Which condition below allows personal data to be processed legally?

A.

A Data Privacy Impact Assessment (DPIA) should be performed prior to data collection.

B.

Data processing must be previously authorized by the Supervisory Authority.

C.

Holders’ rights must be protected by a privacy policy.

D.

There must be a legitimate basis for data processing.

A good practice is to lock the computer automatically or manually when you are away from the workstation.

The company’s DPO realizes that this procedure is not being followed by employees. This occurrence should be classified in which category?

A.

Classified as a security vulnerability

B.

Classified as a security incident

C.

There is no specific category.

D.

Classified as a data breach

One of the basic principles of the General Data Protection Regulation (GDPR) is subsidiarity.

What is subsidiarity to GDPR?

A.

Personal data can only be collected for explicit, legitimate and specific purposes and cannot be processed for any other purpose.

B.

Only the personal data needed to achieve a specific purpose should be collected.

C.

The least privacy-violating means should be used when processing personal data.

D.

Personal data must be kept for a period not longer than necessary.

According to the GDPR, what is a description of binding corporate rules (BCR)?

A.

A decision on the safety of transferring personal data to a non-EEA country

B.

A set of approved rules on personal data protection used by a group of enterprises

C.

A measure to compensate for the lack of personal data protection in a third country

D.

A set of agreements covering personal data transfers between non-EEA countries

The General Data Protection Regulation (GDPR) in its Article 30 legislates on the Records of treatment activities.

If requested, the controller must provide these records:

A.

To the data processor

B.

To the Data Protection Officer (DPO)

C.

The supervisory authority

D.

To the European Commission