Black Friday Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70special

Exin PDPF Privacy and Data Protection Foundation Exam Practice Test

Page: 1 / 15
Total 149 questions

Privacy and Data Protection Foundation Questions and Answers

Testing Engine

  • Product Type: Testing Engine
$37.5  $124.99

PDF Study Guide

  • Product Type: PDF Study Guide
$33  $109.99
Question 1

Racial or ethnic origin, political opinions, religious or philosophical beliefs, or union membership, as well as the processing of genetic data, biometric data, health data or data relating to a person’s sexual life or sexual orientation.

What does this sentence above refer to?

Options:

A.

Available personal data categories.

B.

Rights categories of data subjects.

C.

Categories of purposes for the processing of personal data.

D.

Personal data categories.

Question 2

A controller discovers that a data subject, who had given consent for the processing of his data, has passed away. What this implies for data processing according to the General Data Protection Regulation (GDPR)?

Options:

A.

With the death of the data owner, the controller can continue processing the data, as they are no longer under the GDPR.

B.

The data can only be processed by the controller respecting the consent provided by the holder.

C.

The controller must delete the data of the holder, since with the death of the holder the consent is automatically revoked.

D.

The controller can process the data of a deceased person as long as it anonymizes the data.

Question 3

A person buys a product at a store located in the European Economic Area (EEA). At the time of purchase, you are asked to fill out a registration form and he informs his personal email.

As is usual in many stores, in the next few days this person will start receiving several marketing emails. He considers the frequency of these emails to be very high. Demanding his rights, he asks the store to delete all his personal data.

What the store must do according to the General Data Protection Regulation (GDPR)?

Options:

A.

The owner does not have this right, since he bought a product in the store, he has the right to send emails with new promotions.

B.

The store has 30 days from the date of receipt of the customer’s request to delete all data at no cost to the customer.

C.

The store must delete customer data from its advertising list. Purchase data cannot be deleted, as financial data has to be kept longer.

Question 4

A company CEO travels to a meeting in another city. He takes a notebook with information about the company’s new projects and acquisitions, which will be the subject of discussion at this meeting. These are the only data stored on the notebook.

The notebook accidentally falls into the hotel’s pool and all data is lost.

What happened, considering the General Data Protection Regulation (GDPR)?

Options:

A.

A security incident

B.

A vulnerability

C.

A data breach

D.

A security risk

Question 5

An Independent Supervisory Authority has several responsibilities. Which of the following is one of these?

Options:

A.

Supervise the application of the General Data Protection Regulation (GDPR).

B.

Assist in the elaboration and adaptation of the specific data protection laws of each country.

C.

Conduct a Data Protection Impact Assessment (DPIA).

D.

Assist in the planning of a Personal Data Protection Management System when requested by the Controller.

Question 6

A person finds that a private videotape showing her in a very intimate situation has been published on a website. She never consented to publication and demands that the video is being removed without undue delay.

According to the GDPR, what should be done next?

Options:

A.

Nothing. The video may be regarded as ‘news’ and, therefore, the website is only exercising its right to freedom of expression and information.

B.

The controller erases the video from the website and, when possible, informs any controller who might

process the same video, that it must be erased.

C.

The controller erases the video from the website. There is no obligation however, to inform others who might have copied it, that it should be erased.

D.

The controller directs the person to seek a lawyer and informs that he cannot exclude before a juridical authorization.

Question 7

According to the GDPR, what is a mandatory topic in a DPIA report?

Options:

A.

Systematic description of the fiduciary duties to ensure compliance to all relevant laws and regulations

B.

An assessment of the necessity and proportionality of the processing operations in relation to the purposes

C.

The documentation of the risks to the rights and freedoms of the data protection officer

D.

The measures envisaged to address the privacy compliance frameworks risks

Question 8

What is the legal status of the GDPR?

Options:

A.

The GDPR is functional law in all member states of the EEA. Some Articles allow for member states law to provide for more specific rules.

B.

The GDPR sets out minimum conditions and requirements. Member states need to pass national laws to meet these minimum requirements.

C.

The GDPR is a recommendation of the European Commission that EEA countries’ law authorities improve their laws on the protection of personal data.

Question 9

A controller can contract out the processing of personal data to another company, provided a written contract between these partners is in place.

Which clause in this contract is a responsibility of the controller?

Options:

A.

To ensure that persons authorized to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

B.

To make available all information necessary to demonstrate compliance with the obligations laid down in the GDPR and allow for and contribute to audits, including inspections.

C.

To process the personal data only on documented instructions, including with regard to transfers of personal data to a third country or an international organization.

D.

To provide sufficient guarantees for appropriate technical and organizational measures in such a manner that processing will meet the requirements of the GDPR.

Question 10

Which of the following types of transfers of personal data outside the European Economic Area (EEA) is allowed?

Options:

A.

Transfer between country governments.

B.

Transfers subject to the law of the countries involved.

C.

Transfers conducted through Standard Contractual Clauses.

D.

Transfers conducted under Compulsory Corporate Rules.

Question 11

A German company wants to enter into a binding contract with a processor in the Netherlands for the processing of sensitive personal data of German data subjects. The Dutch Supervisory Authority is informed of the type of data and the aims of the processing, including the contract describing what data will be processed and what data protection procedures and practices will be in place.

According to the GDPR, what should the Dutch Supervisory Authority do in this scenario?

Options:

A.

Report the data processing to the German Supervisory Authority and leave the supervising to them.

B.

Supervise the processing of personal data in accordance with Dutch Law.

C.

Supervise the processing of personal data in accordance with German Law.

D.

The Dutch Supervisory Authority should check that adequate binding contracts are in place. The German Supervisory Authority should supervise.

Question 12

In what way are online activities of people most effectively used by modern marketers?

Options:

A.

By analyzing the logs of the web server it can be seen which products are top sellers, allowing them to optimize their marketing campaigns for those products.

B.

By tagging users of social media, profiles of their online behavior can be created. These profiles are used to ask them to promote a product.

C.

By tagging visitors of web pages, profiles of their online behavior can be created. These profiles are sold and used in targeted advertisement campaigns.

Question 13

A gentleman has a loan denied by the bank’s system that he has been a customer for many years. He is disgusted, because the loan would make it possible to hold the wedding of his only granddaughter.

He contacts the bank and asks for explanations. He wants to know exactly why his loan was denied and based on what information.

What right is required by the data subject according to the GDPR?

Options:

A.

Right to limitation of treatment

B.

Right to rectification

C.

Data subject’s right of access

D.

Right to object and automated individual decision-making

Question 14

Which data subject right is explicitly defined by the GDPR?

Options:

A.

A copy of personal data must be provided in the format requested by the data subject.

B.

Personal data must always be erased if the data subject requests this.

C.

Access to personal data must be provided free of charge for the data subject.

D.

Personal data must always be changed at the request of the data subject.

Question 15

What is a responsibility of Supervisory Authorities in EEA countries?

Options:

A.

Research on security breaches of corporate information

B.

Supervision of all data processing operations controlled by a controller in an EEA country

C.

Supervision of all data processing operations where the data subjects are residents of an EEA country

Question 16

What is a description of data protection by design and by default?

Options:

A.

Not holding more data than is strictly required for processing

B.

An indication of timeframes if processing relates to erasure

C.

Data may only be collected for explicit and legitimate purposes

D.

An approach that implements data protection from the start (Correct)

Question 17

How are the terms privacy and data protection related?

Options:

A.

Data protection is the right to privacy.

B.

The terms are synonymous.

C.

Privacy includes the right to the protection of personal data.

Question 18

Regarding the Portability Law for data subjects, which option is correct?

Options:

A.

The data subject has the right to object at any time, for reasons related to their particular situation, so that the data is not shared between controllers.

B.

The data subject has the right to ask the controller to rectify, erase or limit the processing of personal data with respect to the data subject if he has shared his data.

C.

The data owner has the right to transmit his data to another controller without the controller that already has the personal data provided being able to prevent it.

D.

The data subject has the right to obtain from the controller the limitation of processing so that the data is shared.

Question 19

Who is responsible for demonstrating the compliance of personal data processing with the General Data Protection Regulation (GDPR)?

Options:

A.

The Data Protection Officer (DPO)

B.

The processor

C.

The controller

D.

The supervisory authority

Question 20

Which of the alternatives describes one of the Supervisory Authority’s responsibilities?

Options:

A.

Supervise the processing of data of holders residing in a country belonging to the European Economic Area (EEA).

B.

Consider the nature of the treatment, and as far as possible, assist the controller in order to enable the controller to fulfill his obligation.

C.

Provide the controller with all necessary information to demonstrate compliance with obligations.

D.

Apply technical and organizational measures to ensure that only personal data that are necessary for each specific purpose of processing are processed.

Question 21

What is the main use of a persistent cookie?

Options:

A.

To save the pages a user has bookmarked in the user’s browser history

B.

To record every keystroke made by a computer user to find out passwords

C.

To ensure that the user’s personal data are stored securely on the server

D.

To personalize the user’s experience of the website during the next visit

Question 22

A company located in France wishes to enter into a compulsory contract with a processor located in Portugal. This contract aims to process sensitive French personal data. The Portuguese Supervisory Authority is informed about this contract and the type of processing.

How should Portuguese Supervisory Authority proceed, in accordance with the General Data Protection Regulation (GDPR)?

Options:

A.

Supervise the processing of personal data according to the guidelines of the Supervisory Authority of Portugal.

B.

Report the data processing to the French Supervisory Authority, which must take over the supervision.

C.

Verify that adequate compulsory contracts have been established and leave supervision to the French Supervisory Authority.

D.

Supervise the processing of personal data in accordance with the French Supervisory Authority legislation.

Page: 1 / 15
Total 149 questions