PDPF Exam Questions
145 real PDPF exam questions with expert-verified answers and explanations. Page 1 of 3.
- Question #1Privacy by Design and by Default
What is the essence of the principle 'Full Lifecycle Protection'?
Full Lifecycle ProtectionPrivacy by Designdata securitydata collection - Question #2Data protection breaches
A processor is instructed to report on customers who bought a product both last month and at least once in the three months before that. Unfortunately, the processor makes a mistak...
data breach notificationprocessor obligationscontroller dutiesincident response - Question #3Supervisory authorities and enforcement
The Supervisory Authority is notified whenever an organization intends to process personal data, except for some specific situations. The Supervisory Authority keeps a publicly acc...
supervisory authoritynotification registercompliance assessmentsensitive data - Question #4Key concepts of data protection
In what way are online activities of people most effectively used by modern marketers?
online trackingbehavioral profilingweb analyticsdigital marketing - Question #5Supervisory authorities and enforcement
A German company wants to enter into a binding contract with a processor in the Netherlands for the processing of sensitive personal data of German data subjects. The Dutch Supervi...
supervisory authority jurisdictioncross-border processinglead supervisory authoritysensitive data - Question #6Rights of the data subject
A person finds that a private videotape showing her in a very intimate situation has been published on a website. She never consented to publication and demands that the video is b...
right to erasureright to be forgottenconsent withdrawalintimate content - Question #7Data processing and consent
For processing of personal data to be legal, a number of requirements must be fulfilled. What is a requirement for lawful personal data processing?
lawful processinglegal basislegitimate groundsprocessing conditions - Question #8International data transfers
Under what EU legislation is data transfer between the EEA and the U.S.
Privacy Shieldadequacy decisionEU-US data transferEEA transfers - Question #9Privacy by Design and by Default
According to the GDPR, for which situations should a Data Protection Impact Assessment (DPIA) be conducted?
DPIAhigh risk processingprivacy impact assessmentrisk triggers - Question #10Data protection breaches
While paying with a credit card, the card is skimmed (i.e. the data on the magnetic strip is stolen). The magnetic strip contains the account number, expiration date, cardholder's...
data breachcard skimmingbreach classificationpersonal data theft - Question #11Rights of the data subject
Someone regularly receives offers from a store where he purchased something five years ago. He wants the company to stop sending offers and to wipe his personal data. Which aspect...
right to erasurewithdraw consentmarketing opt-outdata subject rights - Question #12Key concepts of data protection
Important technical requirements set out in the General Data Protection Regulation (GDPR) are about data quality. One is the obligation to ensure appropriate security, including pr...
data minimizationdata qualitytechnical requirementsadequacy and relevance - Question #13Privacy by Design and by Default
According to the GDPR, what is a mandatory topic in a DPIA report?
DPIAnecessity assessmentproportionalityprocessing operations - Question #14Roles and responsibilities
What is the role of the one assigned the responsibility to govern the purposes and means of processing personal data within an organization, according to the GDPR?
controllerrolesprocessing governancepurposes and means - Question #15Supervisory authorities and enforcement
The GDPR states that records of processing activities must be kept by the controller. To whom must the controller make these records available, if requested?
records of processingsupervisory authoritycontroller obligationsaccountability - Question #16Data protection breaches
Which situation is considered a data breach according to the GDPR?
data breachunauthorized accessbreach definitionunattended device - Question #17Data processing and consent
A controller discovers that a data subject, who had given consent for the processing of his data, has passed away. What this implies for data processing according to the General Da...
deceased personsGDPR scopeconsent validitydata subject definition - Question #18Privacy by Design and by Default
According to the GDPR, what is the main reason to consider data protection in the initial design phase?
Privacy by Designdesign phaseprivacy by defaultdata protection rationale - Question #19Data processing and consent
When does the GDPR require data subjects consent to a cookie?
cookiesconsentonline identifierePrivacy - Question #20Data protection breaches
A personal data breach has occurred, and the controller is writing a draft notification for the supervisory authority. The following information is already in the notification: - T...
breach notificationsupervisory authoritynotification contentmitigation measures - Question #21Rights of the data subject
The General Data Protection Regulation (GDPR) formalizes the data subject's right to data portability. What is the objective of data portability?
data portabilitydata subject rightsGDPRpersonal data transfer - Question #22Key concepts of data protection
Personal data as defined in the GDPR can be divided into several types. One of these types is described: Data that directly or indirectly reveal someone's racial or ethnic backgrou...
special category datasensitive personal datapersonal data typesGDPR definitions - Question #23Key concepts of data protection
The General Data Protection Regulation (GDPR) is based on the principles of proportionality and subsidiarity. What is the meaning of "proportionality" in this context?
proportionalitydata minimizationGDPR principlesdata adequacy - Question #24Supervisory authorities and enforcement
What is a responsibility of Supervisory Authorities in EEA countries?
supervisory authoritydata processing supervisionEEAcontroller oversight - Question #25Roles and responsibilities
A controller can contract out the processing of personal data to another company, provided a written contract between these partners is in place. Which clause in this contract is a...
controller responsibilitiesdata processing agreementprocessor contractGDPR obligations - Question #26Key concepts of data protection
What is the purpose of Data Life Cycle Management (DLM)?
data lifecycle managementGDPR compliancepersonal datadata protection - Question #27Data protection breaches
An architect, leaving a building site, puts his laptop for a moment beside his car on the road, while answering his phone. When driving away he sees in the mirror his laptop being...
data breachsecurity incidentpersonal data definitionGDPR breach criteria - Question #28Data processing and consent
What is considered a personal data processing for the General Data Protection Regulation (GDPR)?
personal data processingGDPR definitionsdata processing activitiespersonal data - Question #29Data protection breaches
Which cause is a data breach according to the GDPR?
data breach definitionGDPR breach criteriapersonal datasecurity breach - Question #30Privacy by Design and by Default
"The controller shall implement appropriate technical and organizational measures for ensuring that (...) only personal data which are necessary for each specific purpose of the pr...
privacy by designdata protection by defaultdata minimizationGDPR Article 25 - Question #31Key concepts of data protection
What does the principle of 'data minimization' mean?
data minimizationGDPR principlespersonal data adequacydata protection principles - Question #32Data protection breaches
According to Article.33 of the GDPR the controller shall without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data...
breach notificationGDPR penaltiesArticle 33administrative fines - Question #33Introduction to privacy and data protection
How are the terms privacy and data protection related?
privacydata protectionfundamental rightsGDPR concepts - Question #34Introduction to privacy and data protection
What is the definition of privacy related to the General Data protection Regulation (GDPR)?
privacy definitionfundamental rightsGDPRprivate life - Question #35Introduction to privacy and data protection
What is the most important difference between the 95/46/EC and the GDPR?
GDPR vs Directive 95/46/ECEEA member statesGDPR applicabilityregulation vs directive - Question #36Supervisory authorities and enforcement
What should be done by the EU member states and is not a responsibility of the supervisory authorities?
member state obligationssupervisory authority powersGDPR penaltiesenforcement - Question #37International data transfers
Personal data can be transferred outside of the EE
binding corporate rulesinternational data transfersBCREEA transfers - Question #38Data processing and consent
The General Data Protection Regulation (GDPR) allows processing of personal data only for purposes explicitly permitted by law. A tax advisor wants to file income tax returns for a...
lawful basisexplicit consentdata processing groundsGDPR Article 6 - Question #39International data transfers
What does the GDPR concept of 'binding corporate rules' (BCR) imply?
binding corporate rulesBCR definitioninternational data transfersmultinational enterprises - Question #40Roles and responsibilities
A written contract between a controller and a processor is called a data processing agreement. According to the GDPR, what does not have to be covered in the written contract?
data processing agreementcontroller processor contractDPA contentGDPR Article 28 - Question #41Introduction to privacy and data protection
The General Data Protection Regulation (GDPR) came into effect on May 25, 2018, what is the legal status of this regulation?
GDPR legal statusEU regulationbinding lawmember states - Question #42Key concepts of data protection
GDPR quotes in one of its principles that personal data should be adequate, relevant and limited to what is necessary in relation to its purpose. What principle is this?
data minimizationGDPR principlespersonal datapurpose limitation - Question #43Data protection breaches
A company is planning to process personal dat
security vulnerabilitypersonal data breachsecurity incidentdefinitions - Question #44Introduction to privacy and data protection
Which organizations need to comply with the General Data Protection Regulation (GDPR)?
GDPR territorial scopeextraterritorial applicationEU organizationscompliance - Question #45Roles and responsibilities
In the contract between the controller and processor for the processing of personal data, which of the options below represents the sole responsibility of the Controller?
controller responsibilitiesprocessor contracttechnical measuresdata processing agreement - Question #46Privacy by Design and by Default
Which of the parts below can implement data protection by design (from conception)?
privacy by designprocessor roleimplementationcontroller - Question #47Rights of the data subject
After appearing in a photo posted by a friend on a social network, a person felt embarrassed and decided that he wants the photo to be deleted. According to the General Data Protec...
right to erasureright to be forgottensocial mediadata subject rights - Question #48Privacy by Design and by Default
What is the main objective of the "Lifecycle Protection" principle?
lifecycle protectiondata securityprivacy by designsecurity measures - Question #49Key concepts of data protection
Which of the following options describes the concept of data minimization?
data minimizationGDPR principlespurpose limitationdata processing - Question #50International data transfers
Which of the following types of transfers of personal data outside the European Economic Area (EEA) is allowed?
international transfersEEAbinding corporate rulesstandard contractual clauses