Summer Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: exc65

The General Data Protection Regulation (GDPR) is related to the protection of personal data. What is the definition of personal data?

A.

Preservation of confidentiality, integrity and availability of information

B.

Any information regarding an identified or identifiable natural person

C.

Any information that European citizens want to protect

D.

Data that directly or indirectly reveals racial or ethnic origins, someone’s religious views, and their data related to sexual health and habits

The Supervisory Authority is notified whenever an organization intends to process personal data, except for some specific situations. The Supervisory Authority keeps a publicly accessible register of these data processing operations.

What else is a legal obligation of the Supervisory Authority in reaction to such a notification?

A.

To assess compliance with the law in all classes where sensitive personal data is processed

B.

To assess the legitimacy of operations that involve specific risks for the data subjects

C.

To assess the legitimacy of binding contract(s) between the controller and the data processor(s)

D.

To give out a license for the data processing, specifying the types of personal data which are allowed

A security breach has occurred in an information system that also holds personal data. According to the GDPR, what is the very first thing the controller must do?

A.

Assess the risk of adverse effects to the data subjects using a data protection impact assessment (DPIA)

B.

Ascertain whether the breach may have resulted in loss or unlawful processing of personal data

C.

Report the breach immediately to all data subjects and the relevant supervisory authority

D.

Assess whether personal data of a sensitive nature has or may have been unlawfully processed

In the European Union we have: Directives and Regulations. What is the difference between them?

A.

The regulation provides guidance for EU Member States and they can create their own laws to conform to the regulation. A directive has the force of law and all EU Member States must follow it without changing it.

B.

The directive provides guidance for EU member states and they can create their own laws to suit the directive. A regulation has the force of law and all EU Member States must follow it without changing it.

The General Data Protection Regulation (GDPR) allows processing of personal data only for purposes explicitly permitted by law. A tax advisor wants to file income tax returns for a neighbor.

Which of the legitimate grounds in the GDPR applies?

A.

Processing of the personal data is permitted in this case with explicit consent of the data subject.

B.

Processing of the personal data is permitted because this is necessary for compliance with a legal obligation to which the controller is subject.

C.

Processing of personal data is permitted in the course of a purely personal or household activity.

Organizations are obliged to keep a number of records to demonstrate compliance with the GDPR. Which record is not obligatory according to the GDPR?

A.

A record of notifications sent to the supervisory authority regarding processing of personal data

B.

A record of all intended processing together with the processing purpose(s) and legal justifications

C.

A record of processors including personal data provided and the period this data can be retained

D.

A record of data breaches with all relevant characteristics, including notifications

Someone regularly receives offers from a store where he purchased something five years ago. He wants the company to stop sending offers and to wipe his personal data.

Which aspect of the rights of a data subject in the General Data Protection Regulation (GDPR) requires the company to comply?

A.

The right to erasure

B.

The right to rectification

C.

The right to restriction of processing

D.

The right to withdraw consent

According to the GDPR, what is a task of a supervisory authority?

A.

Investigate security breaches of corporate information

B.

Implement technical and organizational measures to ensure compliance

C.

Monitor and enforce the application of the GDPR

Which of the options below is classified as a personal data breach under the GDPR?

A.

Personal data processed without the consent of the controller.

B.

A server is attacked and exploited by a hacker.

C.

Data accessed by employees without permission.

D.

Strategic company data is mistakenly shared.

A person who works for a union took home a draft newsletter to finish it. The thumb drive containing the draft and contact list has been lost. To whom, among others, this data breach should be reported?

A.

To all members of the contact list

B.

To the Union staff

C.

To the police