PDPF Exam Questions
145 real PDPF exam questions with expert-verified answers and explanations. Page 2 of 3.
- Question #51Data protection breaches
Which of these options is an example of a data breach?
data breachpersonal data losssecurity incidentdefinitions - Question #52Introduction to privacy and data protection
Data protection and privacy are closely related terms. Which of these options best represent this relationship?
privacydata protectionpersonal datarelationship - Question #53Data protection breaches
After notifying the supervisory authority, what should be the first action the controller must take when it finds a security breach where unauthorized people have accessed personal...
data breach responsecontroller obligationsbreach managementsupervisory authority notification - Question #54Key concepts of data protection
Which of the following conflicts with the principle of limiting the purposes?
purpose limitationdata sellingconsentGDPR principles - Question #55Introduction to privacy and data protection
What year did the General Data Protection Regulation (GDPR) come into force?
GDPR historyregulation timeline2018EU law - Question #56Supervisory authorities and enforcement
How does a Supervisory Authority collaborate to the application of GDPR?
supervisory authorityGDPR enforcementmonitoringcompliance - Question #57Supervisory authorities and enforcement
Which of the alternatives describes one of the Supervisory Authority's responsibilities?
supervisory authoritydata processing supervisionEU residentsresponsibilities - Question #58Rights of the data subject
How does GDPR regulate this specific case? A woman uses the services of a gym in the city where she lives. Yet she will move to another town. So, she requests the current gym to tr...
data portabilityright to portabilitydata transfercontroller obligations - Question #59Data protection breaches
A company CEO travels to a meeting in another city. He takes a notebook with information about the company's new projects and acquisitions, which will be the subject of discussion...
security incidentpersonal data breachGDPR definitionsdata loss - Question #60Supervisory authorities and enforcement
When a data breach occurs in a company that has branches in several countries of the European Union, which supervisory authority is competent to take the appropriate measures?
lead supervisory authoritymain establishmentcross-border processingone-stop-shop - Question #61Supervisory authorities and enforcement
The Control Authority may impose fines on organizations that are not meeting the mandatory requirements of the General Data Protection Regulation (GDPR).
supervisory authorityfinesGDPR enforcementmandatory requirements - Question #62Rights of the data subject
A person buys a product at a store located in the European Economic Area (EEA). At the time of purchase, you are asked to fill out a registration form and he informs his personal e...
right to erasuremarketing emailsdata retentionpurchase data - Question #63Introduction to privacy and data protection
Which of the following options is provided for in the GDPR and can be made by Member States?
Member Statesnational provisionsGDPR implementationlegislative competence - Question #64Introduction to privacy and data protection
The GDPR contains several items. Which of these contains mandatory requirements?
GDPR articlesrecitalsmandatory requirementsGDPR structure - Question #65Introduction to privacy and data protection
What is the main purpose of the General Data Protection Regulation (GDPR)?
GDPR scopeterritorial scopeEEAdata subjects - Question #66Data protection breaches
A company's director's notebook is accidentally wet, which permanently damages the equipment so that it cannot recover its data. The lost data concerned the financial reports of th...
security incidentdata lossavailabilityincident classification - Question #67Data processing and consent
Which condition below allows personal data to be processed legally?
lawful basisdata processinglegal groundsArticle 6 - Question #68Roles and responsibilities
When personal data are processed, who is ultimately responsible for demonstrating compliance with the GDPR?
controlleraccountabilitycompliance responsibilitydata protection officer - Question #69Introduction to privacy and data protection
The word privacy is never mentioned in the General Data Protection Regulation (GDPR) text. Despite this, what would be the best definition of the privacy according to the Regulatio...
privacy definitionprivate lifefamily lifefundamental rights - Question #70Key concepts of data protection
One of the basic principles of the General Data Protection Regulation (GDPR) is subsidiarity. What is subsidiarity to GDPR?
subsidiarityproportionalityprivacy principlesdata minimization - Question #71Data protection breaches
The controller responsible for the UK Child Sexual Abuse Investigation body reported a data breach to the supervisory authority in the UK on 28 February 2019. People who had regist...
data breach notificationsupervisory authoritybreach categorizationrisk assessment - Question #72Key concepts of data protection
In its Article 9 the GDPR categorizes some types of personal data as "sensitive". Of these below which are considered sensitive?
sensitive dataspecial categoriesArticle 9medical data - Question #73Data protection breaches
A secretary at a pediatric cardiology clinic instead of sending the doctor the list of patients scheduled for the day, sends it to all those responsible registered for the children...
health data breachbreach notificationsupervisory authoritydata subject notification - Question #74Data protection breaches
A breach of security that leads to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored or otherwis...
personal data breachGDPR definitionsecurity breachterminology - Question #75Introduction to privacy and data protection
In the European Union we have: Directives and Regulations. What is the difference between them?
EU DirectiveEU Regulationlegal instrumentsMember States - Question #76Data protection breaches
A good practice is to lock the computer automatically or manually when you are away from the workstation. The company's DPO realizes that this procedure is not being followed by em...
security vulnerabilityphysical securityworkstationincident classification - Question #77Privacy by Design and by Default
Which option below defines correctly data protection by design (from conception)?
Privacy by DesignArticle 25data protection by designGDPR principles - Question #78International data transfers
According to the GDPR, what is a description of binding corporate rules (BCR)?
binding corporate rulesBCRinternational transfersmultinational groups - Question #79Data protection breaches
We know that when a personal data breach occurs, the data controller (Controller) must notify the Supervisory Authority within 72 hours, without justified delay. However, should th...
72-hour notificationbreach reportingdelayed notificationsupervisory authority - Question #80Data protection breaches
Which of the options below is classified as a personal data breach under the GDPR?
personal data breachunauthorized accessincident classificationbreach scenarios - Question #81International data transfers
What is called the adequacy decision that allows data transfer between the United States and the European Economic Area (EEA)?
Privacy Shieldadequacy decisionUS-EEA transferinternational transfers - Question #82Key concepts of data protection
Racial or ethnic origin, political opinions, religious or philosophical beliefs, or union membership, as well as the processing of genetic data, biometric data, health data or data...
special categoriessensitive personal dataracial originbiometric data - Question #83Data protection breaches
While performing a backup, a data server disk crashed. Both the data and the backup are lost. The disk contained personal data, but no special category personal dat
data breachpersonal data losssecurity incidentavailability breach - Question #84Roles and responsibilities
What is the definition of Controller according to GDPR?
controller definitionGDPR rolespurpose determinationdata controller - Question #85Rights of the data subject
A gentleman has a loan denied by the bank's system that he has been a customer for many years. He is disgusted, because the loan would make it possible to hold the wedding of his o...
automated decision-makingright to explanationArticle 22loan denial - Question #87Roles and responsibilities
How should data protection between the processor and controller be regulated in accordance with the General Data Protection Regulation (GDPR)?
controller-processor contractdata processing agreementArticle 28processor relationship - Question #88Key concepts of data protection
How is Data Lifecycle Management (DLM) related to data protection?
Data Lifecycle ManagementDLMdata flowdata lifecycle - Question #89Data processing and consent
According to the principle of purpose limitation, data should not be processed beyond the legitimate purpose defined. However, further processing is allowed in a few specific cases...
purpose limitationfurther processingdirect marketingdata processing principles - Question #90Roles and responsibilities
What is the definition of Processor according to GDPR?
processor definitionGDPR rolesdata processoron behalf of - Question #91Introduction to privacy and data protection
What is the main difference between Directive 95/46 / EC and the General Data Protection Regulation (GDPR)?
GDPR vs DirectiveDirective 95/46/ECregulation vs directiveEU data law history - Question #92Supervisory authorities and enforcement
The General Data Protection Regulation (GDPR) in its Article 30 legislates on the Records of treatment activities. If requested, the controller must provide these records:
records of processing activitiesArticle 30supervisory authoritycontroller obligations - Question #93Supervisory authorities and enforcement
Regarding the Supervisory Authority's "Investigative Powers", it is correct to state:
supervisory authority powersinvestigative powersGDPR enforcementGDPR violations - Question #94International data transfers
According to the General Data Protection Regulation (GDPR) which covers the concept "Compulsory Corporate Rules"?
Binding Corporate RulesBCRintra-group transfersinternational transfer mechanism - Question #95Data protection breaches
Article 33 of the GDPR deals with "Notification of a personal data breach to the supervisory authority". Paragraph 3 sets out the minimum information that must be included in this...
breach notificationArticle 33notification contentDPO contact - Question #96Data protection breaches
A controller asks a processor to produce a report containing customers who have purchased a particular product more than once in the past 6 months. The processor provides services...
processor obligationsbreach notification chaincross-controller data mixingArticle 33 - Question #97Key concepts of data protection
What is the purpose of Data Lifecycle Management (DLM)?
Data Lifecycle ManagementDLMGDPR compliancedata lifecycle - Question #98Introduction to privacy and data protection
offense under European law. What kind of offense is this?
privacy offenseEuropean lawprivacy violationoffense classification - Question #99Key concepts of data protection
The General Data Protection Regulation (GDPR) is related to the protection of personal dat
personal data definitionidentifiable natural personGDPR Article 4data subject - Question #100Rights of the data subject
Regarding the Portability Law for data subjects, which option is correct?
data portabilityright to portabilityArticle 20data subject rights - Question #101Roles and responsibilities
A company located in France wishes to enter into a compulsory contract with a processor located in Portugal. This contract aims to process sensitive French personal dat
DPO responsibilitiescross-border processingdata processing contractsupervisory authority cooperation