Easter Special Sale - Limited Time 60% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 575363r9

Welcome To DumpsPedia

PDPF Sample Questions Answers

Questions 4

A secretary at a pediatric cardiology clinic instead of sending the doctor the list of patients scheduled for the day, sends it to all those responsible registered for the children with scheduled appointments.

According to the GDPR, does the Supervisory Authority need to be notified? And those responsible for the data holders?

Options:

A.

The Supervisory Authority must be notified, but there is no need to notify those responsible for the data subjects, as whoever had access to the data is also someone in the same situation.

B.

The Supervisory Authority must be notified and also those responsible for the holders who had their data exposed.

C.

There is no need to notify the Supervisory Authority, however those responsible for the holders who had

their data exposed must be notified.

D.

There is no need to notify the Supervisory Authority or those responsible for the data subjects, as whoever had access to the data is also someone in the same situation.

Buy Now
Questions 5

The General Data Protection Regulation (GDPR) formalizes the data subject’s right to data portability.

What is the objective of data portability?

Options:

A.

The controller has the right to move the data subject’s personal data from one organization to another.

B.

The data subject has the right to move personal data concerning him or her.

C.

The data subject has the right to move his/her personal data when moving to another country.

D.

The Supervisory Authority authorizes the movement of personal data.

Buy Now
Questions 6

According to the GDPR, when is a data protection impact assessment (DPIA) obligatory?

Options:

A.

When a project includes technologies or processes that use personal data

B.

When processing is likely to result in a high risk to the rights of data subjects

C.

When similar processing operations with comparable risks are repeated

Buy Now
Questions 7

One of the basic principles of the General Data Protection Regulation (GDPR) is subsidiarity.

What is subsidiarity to GDPR?

Options:

A.

Personal data can only be collected for explicit, legitimate and specific purposes and cannot be processed for any other purpose.

B.

Only the personal data needed to achieve a specific purpose should be collected.

C.

The least privacy-violating means should be used when processing personal data.

D.

Personal data must be kept for a period not longer than necessary.

Buy Now
Questions 8

The GDPR refers to the principles of proportionality and subsidiarity. What is the meaning of subsidiarity in this context?

Options:

A.

Personal data may only be processed when there are no other means to achieve the purposes.

B.

Personal data cannot be reused without explicit and informed consent.

C.

Personal data can only be processed in accordance with the purpose specification.

D.

Personal data must be adequate, relevant and not excessive in relation to the purposes.

Buy Now
Questions 9

What is considered a personal data processing for the General Data Protection Regulation (GDPR)?

Options:

A.

Analysis of data regarding the cause of death in the last 10 years.

B.

Creating a backup with records of names, addresses, enrollment of students.

C.

Conducting analysis of personal data related to health issues, but which have previously been anonymized.

D.

Statistical publication with intention to vote, help anonymously.

Buy Now
Questions 10

A controller discovers that a data subject, who had given consent for the processing of his data, has passed away. What this implies for data processing according to the General Data Protection Regulation (GDPR)?

Options:

A.

With the death of the data owner, the controller can continue processing the data, as they are no longer under the GDPR.

B.

The data can only be processed by the controller respecting the consent provided by the holder.

C.

The controller must delete the data of the holder, since with the death of the holder the consent is automatically revoked.

D.

The controller can process the data of a deceased person as long as it anonymizes the data.

Buy Now
Questions 11

In the GDPR, some types of personal data are regarded as special category personal data. Which personal data are considered special category personal data?

Options:

A.

An address list of members of a political party

B.

A genealogical register of someone’s ancestors

C.

A list of payments made using a credit card

Buy Now
Questions 12

According to the GDPR, what is a mandatory topic in a DPIA report?

Options:

A.

Systematic description of the fiduciary duties to ensure compliance to all relevant laws and regulations

B.

An assessment of the necessity and proportionality of the processing operations in relation to the purposes

C.

The documentation of the risks to the rights and freedoms of the data protection officer

D.

The measures envisaged to address the privacy compliance frameworks risks

Buy Now
Questions 13

Who is responsible for demonstrating the compliance of personal data processing with the General Data Protection Regulation (GDPR)?

Options:

A.

The Data Protection Officer (DPO)

B.

The processor

C.

The controller

D.

The supervisory authority

Buy Now
Questions 14

Racial or ethnic origin, political opinions, religious or philosophical beliefs, or union membership, as well as the processing of genetic data, biometric data, health data or data relating to a person’s sexual life or sexual orientation.

What does this sentence above refer to?

Options:

A.

Available personal data categories.

B.

Rights categories of data subjects.

C.

Categories of purposes for the processing of personal data.

D.

Personal data categories.

Buy Now
Questions 15

Data protection and privacy are closely related terms. Which of these options best represent this relationship?

Options:

A.

Privacy is a part of data protection that aims to keep personal data confidential.

B.

Data protection is a part of privacy that aims to keep personal data confidential.

C.

The two terms have the same meaning. They are synonymous.

D.

Without protection of personal data there is no privacy.

Buy Now
Questions 16

How should data protection between the processor and controller be regulated in accordance with the General Data Protection Regulation (GDPR)?

Options:

A.

Contract

B.

Supervisory Authority endorsement.

C.

Compulsory Corporate Rules.

D.

Standard contractual clauses.

Buy Now
Questions 17

A company CEO travels to a meeting in another city. He takes a notebook with information about the company’s new projects and acquisitions, which will be the subject of discussion at this meeting. These are the only data stored on the notebook.

The notebook accidentally falls into the hotel’s pool and all data is lost.

What happened, considering the General Data Protection Regulation (GDPR)?

Options:

A.

A security incident

B.

A vulnerability

C.

A data breach

D.

A security risk

Buy Now
Questions 18

After appearing in a photo posted by a friend on a social network, a person felt embarrassed and decided that he wants the photo to be deleted.

According to the General Data Protection Regulation (GDPR), does that person have the right to delete this photo?

Options:

A.

False

B.

True

Buy Now
Questions 19

A company located in France wishes to enter into a compulsory contract with a processor located in Portugal. This contract aims to process sensitive French personal data. The Portuguese Supervisory Authority is informed about this contract and the type of processing.

How should Portuguese Supervisory Authority proceed, in accordance with the General Data Protection Regulation (GDPR)?

Options:

A.

Supervise the processing of personal data according to the guidelines of the Supervisory Authority of Portugal.

B.

Report the data processing to the French Supervisory Authority, which must take over the supervision.

C.

Verify that adequate compulsory contracts have been established and leave supervision to the French Supervisory Authority.

D.

Supervise the processing of personal data in accordance with the French Supervisory Authority legislation.

Buy Now
Questions 20

Which of the following conflicts with the principle of limiting the purposes?

Options:

A.

The data is sold to another company without the consent of the data subject.

B.

Adapt the data to the purpose of the treatment.

C.

Store the data in a way that allows the identification of the data subjects.

D.

Data is used in an obscure manner to the data subject.

Buy Now
Questions 21

A person buys a product at a store located in the European Economic Area (EEA). At the time of purchase, you are asked to fill out a registration form and he informs his personal email.

As is usual in many stores, in the next few days this person will start receiving several marketing emails. He considers the frequency of these emails to be very high. Demanding his rights, he asks the store to delete all his personal data.

What the store must do according to the General Data Protection Regulation (GDPR)?

Options:

A.

The owner does not have this right, since he bought a product in the store, he has the right to send emails with new promotions.

B.

The store has 30 days from the date of receipt of the customer’s request to delete all data at no cost to the customer.

C.

The store must delete customer data from its advertising list. Purchase data cannot be deleted, as financial data has to be kept longer.

Buy Now
Questions 22

A controller can contract out the processing of personal data to another company, provided a written contract between these partners is in place.

Which clause in this contract is a responsibility of the controller?

Options:

A.

To ensure that persons authorized to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

B.

To make available all information necessary to demonstrate compliance with the obligations laid down in the GDPR and allow for and contribute to audits, including inspections.

C.

To process the personal data only on documented instructions, including with regard to transfers of personal data to a third country or an international organization.

D.

To provide sufficient guarantees for appropriate technical and organizational measures in such a manner that processing will meet the requirements of the GDPR.

Buy Now
Questions 23

The Supervisory Authority is notified whenever an organization intends to process personal data, except for some specific situations. The Supervisory Authority keeps a publicly accessible register of these data processing operations.

What else is a legal obligation of the Supervisory Authority in reaction to such a notification?

Options:

A.

To assess compliance with the law in all classes where sensitive personal data is processed

B.

To assess the legitimacy of operations that involve specific risks for the data subjects

C.

To assess the legitimacy of binding contract(s) between the controller and the data processor(s)

D.

To give out a license for the data processing, specifying the types of personal data which are allowed

Buy Now
Questions 24

Important technical requirements set out in the General Data Protection Regulation (GDPR) are about data quality. One is the obligation to ensure appropriate security, including protection against unauthorized or unlawful processing.

What is another important technical requirement?

Options:

A.

To ascertain that personal data collection is adequate, relevant and limited to what is necessary in relation to the purposes

B.

To control that data collected for specified, explicit and legitimate purposes is not further processed for other purposes

C.

To keep personal data accurate and up to date, ensuring that inaccurate data are erased or rectified without delay

D.

To make sure that personal data is processed lawfully, fairly and in transparent manner in relation to the data subject

Buy Now
Questions 25

A person finds that a private videotape showing her in a very intimate situation has been published on a website. She never consented to publication and demands that the video is being removed without undue delay.

According to the GDPR, what should be done next?

Options:

A.

Nothing. The video may be regarded as ‘news’ and, therefore, the website is only exercising its right to freedom of expression and information.

B.

The controller erases the video from the website and, when possible, informs any controller who might

process the same video, that it must be erased.

C.

The controller erases the video from the website. There is no obligation however, to inform others who might have copied it, that it should be erased.

D.

The controller directs the person to seek a lawyer and informs that he cannot exclude before a juridical authorization.

Buy Now
Questions 26

What is the purpose of Data Lifecycle Management (DLM)?

Options:

A.

Ensure data integrity and its periodic update

B.

Ensure data confidentiality and availability throughout its useful life.

C.

Ensure that the processing of personal data, throughout its useful life complies with the GDPR

D.

Ensure data confidentiality throughout its useful life, from collection to deletion.

Buy Now
Questions 27

When is a Data Protection Impact Assessment (DPIA) under the General Data Protection Regulation (GDPR) mandatory?

Options:

A.

Application of new technologies that may imply a high risk to the rights and freedoms of data subjects.

B.

There is no security policy and information security risk analysis.

C.

In all types of personal data processing.

Buy Now
Questions 28

In what way are online activities of people most effectively used by modern marketers?

Options:

A.

By analyzing the logs of the web server it can be seen which products are top sellers, allowing them to optimize their marketing campaigns for those products.

B.

By tagging users of social media, profiles of their online behavior can be created. These profiles are used to ask them to promote a product.

C.

By tagging visitors of web pages, profiles of their online behavior can be created. These profiles are sold and used in targeted advertisement campaigns.

Buy Now
Questions 29

Subcontracting treatment is regulated by contract or other regulatory act under Union or Member State law, which links the processor to the controller.

What this contract or other regulatory act stipulates?

Options:

A.

A process for testing, assessing and regularly evaluating the effectiveness of technical and organizational measures to ensure safe treatment.

B.

The processor assists the driver through technical and organizational measures to enable it to fulfill its obligation to respond to requests from data subjects.

C.

The description of categories of data subjects and categories of personal data

D.

The purpose of data processing

Buy Now
Questions 30

While paying with a credit card, the card is skimmed (i.e. the data on the magnetic strip is stolen). The magnetic strip contains the account number, expiration date, cardholder’s name and address, PIN number and more.

What kind of a data breach is this?

Options:

A.

Material

B.

Non-material

C.

Verbal

Buy Now
Questions 31

What is the relationship between data protection and privacy?

Options:

A.

Data protection and privacy are synonyms and have the same meaning.

B.

Data protection refers to the measures needed to protect a person’s privacy.

C.

Data protection is the part of privacy that protects a person’s physical integrity.

Buy Now
Questions 32

The General Data Protection Regulation (GDPR) is often known as the “European privacy law”. What is the relationship between ‘privacy’ and ‘data protection’?

Options:

A.

Privacy is a part of data protection that aims to keep personal data confidential.

B.

Data protection is a part of privacy that aims to keep personal data confidential.

C.

The two terms have the same meaning. They are synonyms.

D.

Data protection is the necessary measures to protect an individual’s privacy.

Buy Now
Questions 33

How does a Supervisory Authority collaborate to the application of GDPR?

Options:

A.

Assists in the implementation of a data protection management system (at controller request).

B.

Monitor and enforce the application of this Regulation.

C.

Perform a Data Privacy Impact Analysis (DPI) at the request of the Data Protection Officer – DPO.

D.

Determines technical safety measures to be applied to the controller.

Buy Now
Questions 34

What is the main difference between Directive 95/46 / EC and the General Data Protection Regulation (GDPR)?

Options:

A.

The GDPR offers guidance for EU Member States and can create their own laws to comply with the regulation. Directive 95/46 / EC has the force of law and all EU Member States must follow it without changing.

B.

Directive 95/46 / EC offers guidance for EU Member States and can create their own laws to suit the directive. The GDPR has the force of law and all EU Member States must follow it without changing it.

Buy Now
Questions 35

What is the main purpose of the General Data Protection Regulation (GDPR)?

Options:

A.

Protecting the data of everyone in Europe.

B.

Protect the data of everyone in the world.

C.

Protect data of data subjects located in the European Economic Area (EEA), regardless of the country of processing.

D.

Protect confidential business data.

Buy Now
Questions 36

Some data processing falls outside of the material scope of the GDPR. What type of processing is not subject to the GDPR?

Options:

A.

Creating a back-up of biometric data for data security purposes

B.

Collecting name and address information for a gymnastics club

C.

Editing personal photographs before printing them at home

Buy Now
Questions 37

While performing a backup, a data server disk crashed. Both the data and the backup are lost. The disk contained personal data, but no special category personal data. The processor states that this is a personal data breach. Is the statement of the processor true?

Options:

A.

Yes, because there were no special category personal data stored on the disk.

B.

No, because no personal data on the disk were processed, only destroyed

C.

Yes, because the personal data on the disk were unlawfully processed.

D.

No, because this is only a security incident and not a data breach

Buy Now
Questions 38

Regarding the Supervisory Authority’s “Investigative Powers”, it is correct to state:

Options:

A.

it has the power to order the suspension of sending data to recipients in third countries or to international organizations

B.

you have the power to order the controller to report a personal data breach to the data subject

C.

it has the power to notify the controller or processor of alleged GDPR violations

D.

it has the power to conduct impact assessments on data privacy

Buy Now
Questions 39

What is the most important difference between the 95/46/EC and the GDPR?

Options:

A.

95/46/EC applies as law in all EEA member states while the GDPR is a guidance.

B.

95/46/EC applies to processing of data on EEA residents worldwide and the GDPR does not.

C.

The GDPR applies as law in all EEA member states while 95/46/EC is a guidance.

D.

The GDPR applies to persons and organizations which process personal data within EEA member states.

The scope of 95/46/EC is more restricted in this aspect.

Buy Now
Questions 40

One of the objectives of a data protection impact assessment (DPIA) is to strengthen the confidence of customers or citizens in the way personal data is processed and privacy is respected. How can a DPIA strengthen the confidence?

Options:

A.

The organization proves that it takes privacy seriously and aims for compliance with the GDPR.

B.

The organization minimizes the risk of costly adjustments in processes or the redesign of systems in a later stage.

C.

The organization prevents non-compliance with the GDPR and minimizes the risk of fines

Buy Now
Questions 41

Which of the alternatives describes one of the Supervisory Authority’s responsibilities?

Options:

A.

Supervise the processing of data of holders residing in a country belonging to the European Economic Area (EEA).

B.

Consider the nature of the treatment, and as far as possible, assist the controller in order to enable the controller to fulfill his obligation.

C.

Provide the controller with all necessary information to demonstrate compliance with obligations.

D.

Apply technical and organizational measures to ensure that only personal data that are necessary for each specific purpose of processing are processed.

Buy Now
Questions 42

The General Data Protection Regulation (GDPR) is related to the protection of personal data. What is the definition of personal data?

Options:

A.

Preservation of confidentiality, integrity and availability of information

B.

Any information regarding an identified or identifiable natural person

C.

Any information that European citizens want to protect

D.

Data that directly or indirectly reveals racial or ethnic origins, someone’s religious views, and their data related to sexual health and habits

Buy Now
Questions 43

Which of these options is an example of a data breach?

Options:

A.

Transfer of personal data outside the EU

B.

Loss of personal data

C.

A security incident related to corporate data.

Buy Now
Questions 44

In the European Union we have: Directives and Regulations. What is the difference between them?

Options:

A.

The regulation provides guidance for EU Member States and they can create their own laws to conform to the regulation. A directive has the force of law and all EU Member States must follow it without changing it.

B.

The directive provides guidance for EU member states and they can create their own laws to suit the directive. A regulation has the force of law and all EU Member States must follow it without changing it.

Buy Now
Exam Code: PDPF
Exam Name: Privacy and Data Protection Foundation
Last Update: May 16, 2024
Questions: 149
$64  $159.99
$48  $119.99
$40  $99.99
buy now PDPF