Labour Day Special - Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: top65certs

Exin PDPF Dumps

Page: 1 / 6
Total 149 questions

Privacy and Data Protection Foundation Questions and Answers

Question 1

One of the objectives of a data protection impact assessment (DPIA) is to strengthen the confidence of customers or citizens in the way personal data is processed and privacy is respected. How can a DPIA strengthen the confidence?

Options:

A.

The organization proves that it takes privacy seriously and aims for compliance with the GDPR.

B.

The organization minimizes the risk of costly adjustments in processes or the redesign of systems in a later stage.

C.

The organization prevents non-compliance with the GDPR and minimizes the risk of fines

Question 2

The GDPR describes the principle of data minimization. How can organizations comply with this principle?

Options:

A.

By applying the concept of least privilege to the personal data collected, stored or otherwise processed.

B.

By limiting access rights to staff who need the personal data for the intended processing operations

C.

By limiting the personal data to what is adequate, relevant and necessary for the processing purposes

D.

By limiting file sizes, through saving all personal data that is processed in the smallest possible format

Question 3

Regarding the Supervisory Authority’s “Investigative Powers”, it is correct to state:

Options:

A.

it has the power to order the suspension of sending data to recipients in third countries or to international organizations

B.

you have the power to order the controller to report a personal data breach to the data subject

C.

it has the power to notify the controller or processor of alleged GDPR violations

D.

it has the power to conduct impact assessments on data privacy

Question 4

A breach of security that leads to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored or otherwise processed. What is the exact term that is associated with this definition in the GDPR?

Options:

A.

Security breach

B.

Personal data breach

C.

Confidentiality violation

D.

Security incident

Question 5

According to the GDPR, what is a mandatory topic in a DPIA report?

Options:

A.

Systematic description of the fiduciary duties to ensure compliance to all relevant laws and regulations

B.

An assessment of the necessity and proportionality of the processing operations in relation to the purposes

C.

The documentation of the risks to the rights and freedoms of the data protection officer

D.

The measures envisaged to address the privacy compliance frameworks risks

Question 6

A secretary at a pediatric cardiology clinic instead of sending the doctor the list of patients scheduled for the day, sends it to all those responsible registered for the children with scheduled appointments.

According to the GDPR, does the Supervisory Authority need to be notified? And those responsible for the data holders?

Options:

A.

The Supervisory Authority must be notified, but there is no need to notify those responsible for the data subjects, as whoever had access to the data is also someone in the same situation.

B.

The Supervisory Authority must be notified and also those responsible for the holders who had their data exposed.

C.

There is no need to notify the Supervisory Authority, however those responsible for the holders who had

their data exposed must be notified.

D.

There is no need to notify the Supervisory Authority or those responsible for the data subjects, as whoever had access to the data is also someone in the same situation.

Question 7

What is the definition of privacy related to the General Data protection Regulation (GDPR)?

Options:

A.

A situation in which one is not observed or distributed by the government or uninvited people.

B.

The right to respect for a person’s private and family life, his home and his correspondence.

C.

The fundamental right to respect a person’s physical and mental integrity.

D.

The right to be protected against unsolicited intrusion into a computer or network and the processing of personal data by third parties.

Question 8

Which cause is a data breach according to the GDPR?

Options:

A.

illegally obtained corporate data from a human resources management system

B.

Personal data is processed without a binding contract.

C.

Personal data is processed by anyone other than the controller, processor or, possibly, subprocessor

D.

The operation of a vulnerable server in the internal network of the processor

Question 9

Which of the options below is classified as a personal data breach under the GDPR?

Options:

A.

Personal data processed without the consent of the controller.

B.

A server is attacked and exploited by a hacker.

C.

Data accessed by employees without permission.

D.

Strategic company data is mistakenly shared.

Question 10

What is the legal status of the GDPR?

Options:

A.

The GDPR is functional law in all member states of the EEA. Some Articles allow for member states law to provide for more specific rules.

B.

The GDPR sets out minimum conditions and requirements. Member states need to pass national laws to meet these minimum requirements.

C.

The GDPR is a recommendation of the European Commission that EEA countries’ law authorities improve their laws on the protection of personal data.

Question 11

A person buys a product at a store located in the European Economic Area (EEA). At the time of purchase, you are asked to fill out a registration form and he informs his personal email.

As is usual in many stores, in the next few days this person will start receiving several marketing emails. He considers the frequency of these emails to be very high. Demanding his rights, he asks the store to delete all his personal data.

What the store must do according to the General Data Protection Regulation (GDPR)?

Options:

A.

The owner does not have this right, since he bought a product in the store, he has the right to send emails with new promotions.

B.

The store has 30 days from the date of receipt of the customer’s request to delete all data at no cost to the customer.

C.

The store must delete customer data from its advertising list. Purchase data cannot be deleted, as financial data has to be kept longer.

Question 12

While paying with a credit card, the card is skimmed (i.e. the data on the magnetic strip is stolen). The magnetic strip contains the account number, expiration date, cardholder’s name and address, PIN number and more.

What kind of a data breach is this?

Options:

A.

Material

B.

Non-material

C.

Verbal

Question 13

A company located in France wishes to enter into a compulsory contract with a processor located in Portugal. This contract aims to process sensitive French personal data. The Portuguese Supervisory Authority is informed about this contract and the type of processing.

How should Portuguese Supervisory Authority proceed, in accordance with the General Data Protection Regulation (GDPR)?

Options:

A.

Supervise the processing of personal data according to the guidelines of the Supervisory Authority of Portugal.

B.

Report the data processing to the French Supervisory Authority, which must take over the supervision.

C.

Verify that adequate compulsory contracts have been established and leave supervision to the French Supervisory Authority.

D.

Supervise the processing of personal data in accordance with the French Supervisory Authority legislation.

Question 14

Which of the following options describes the concept of data minimization?

Options:

A.

It is the minimization of data storage locations.

B.

It is the decrease in the space allocated for data storage.

C.

It is the limitation of data to the purposes for which it is treated.

D.

It is the use of data for the shortest possible time.

Question 15

The GDPR contains several items. Which of these contains mandatory requirements?

Options:

A.

Recitals

B.

Articles

Question 16

According to the GDPR, what is the main reason to consider data protection in the initial design phase?

Options:

A.

It ensures efficiency in project phases

B.

It ensures privacy by default

C.

It reduces the risk of fraud

D.

It reduces the risk of liability

Question 17

In its Article 9 the GDPR categorizes some types of personal data as “sensitive”.

Of these below which are considered sensitive?

Options:

A.

Date of birth of a person.

B.

A person’s home address.

C.

Soccer team that a person supports.

D.

Result of a medical examination.

Question 18

A controller wants to switch processors. What is necessary to review before making this change, so that it remains GDPR compliant?

Options:

A.

The matrix location of this new processor.

B.

Require the old processor to erase data.

C.

Require the old processor to port the data.

D.

Verify that the new processor has sufficient security guarantees.

Question 19

What is considered a personal data processing for the General Data Protection Regulation (GDPR)?

Options:

A.

Analysis of data regarding the cause of death in the last 10 years.

B.

Creating a backup with records of names, addresses, enrollment of students.

C.

Conducting analysis of personal data related to health issues, but which have previously been anonymized.

D.

Statistical publication with intention to vote, help anonymously.

Question 20

To plan the amount of parking space needed, a local government monitors and saves the license plate number of every car that enters and leaves the city center. They have obtained permission to collect data on the number of cars present in the city center. By comparing the license plate time of entry and exit the number of cars present every moment of each day is calculated. Each month a report is created detailing the average number of cars in the city center at specific moments for every day of the week. At every entrance to the city center, a billboard clearly states what data is collected by whom, the purpose of the processing and the fact that the license plate numbers are saved securely for up to two years, because the measurements will be repeated next year. Which of the basic principles for legitimate processing of personal data is violated in this scenario?

Options:

A.

Personal data are processed in a manner that ensures appropriate security of the personal data.

B.

Personal data are processed in a transparent manner in relation to the data subject

C.

Personal data are kept in a form permitting identification of data subjects for no longer than is necessary.

D.

Personal data are collected for specified, explicit and legitimate purposes and not further processed.

Question 21

How does a Supervisory Authority collaborate to the application of GDPR?

Options:

A.

Assists in the implementation of a data protection management system (at controller request).

B.

Monitor and enforce the application of this Regulation.

C.

Perform a Data Privacy Impact Analysis (DPI) at the request of the Data Protection Officer – DPO.

D.

Determines technical safety measures to be applied to the controller.

Question 22

Which of the following has a data breach under the General Data Protection Regulation (GDPR)?

Options:

A.

A processor, after terminating its contract with the controller, deletes personal data.

B.

A collaborator goes away without locking his workstation.

C.

A backup is restored by the controller to a corrupted personal data server.

D.

A notebook with financial reports from a multinational is stolen.

Page: 1 / 6
Total 149 questions