PDPF Exam Questions
145 real PDPF exam questions with expert-verified answers and explanations. Page 3 of 3.
- Question #102Privacy by Design and by Default
Which of the options below best represents data protection by design?
Privacy by Designdata protection measuresdata minimizationsecurity from collection - Question #103Key concepts of data protection
What is the main purpose of cookies?
cookiesuser identificationbrowser dataweb tracking - Question #104Key concepts of data protection
The Traffic Department of a city wants to know how many cars travel daily in order to plan the number of spaces needed to implement a rotating parking system. To do this, cameras w...
storage limitationdata minimizationtransparencypurpose limitation - Question #105Data processing and consent
We know that when browsing the internet there is a lot of personal data that is collected. One mechanism for collecting this data is cookies. How do marketers use this collected pe...
cookiesbehavioral profilingmarketingpersonal data collection - Question #106Privacy by Design and by Default
What is the main reason for performing data protection by design (from conception)?
Privacy by Designlegal compliancerisk reductiondata protection - Question #107Roles and responsibilities
Subcontracting treatment is regulated by contract or other regulatory act under Union or Member State law, which links the processor to the controller. What this contract or other...
processor obligationscontroller-processor contractdata processing agreementGDPR Article 28 - Question #108Roles and responsibilities
Who should ask for an opinion after conducting an impact assessment on the protection of personal data (DPIA)?
DPIADPO consultationsupervisory authorityprior consultation - Question #109Roles and responsibilities
A controller wants to switch processors. What is necessary to review before making this change, so that it remains GDPR compliant?
processor selectionsecurity guaranteescontroller obligationsGDPR compliance - Question #110Rights of the data subject
A person buys a product at a store located in the European Economic Area (EEA). At the time of purchase, you are asked to fill out a registration form and he informs his personal e...
right to erasureright to be forgottendata subject rightsdeletion request - Question #111Supervisory authorities and enforcement
What is the definition of Supervisory Authority according to the GDPR?
supervisory authorityindependent public authorityGDPR definitionsmember state - Question #112Roles and responsibilities
Who is responsible for demonstrating the compliance of personal data processing with the General Data Protection Regulation (GDPR)?
accountabilitycontroller responsibilityGDPR compliancedata protection - Question #113Data protection breaches
To comply with the General Data Protection Regulation (GDPR) it is necessary to create a procedure for reporting data breaches to the Supervisory Authority. As the controller is a...
data breach notificationDPO consultationbreach proceduresupervisory authority - Question #114Data protection breaches
A person who works for a union took home a draft newsletter to finish it. The thumb drive containing the draft and contact list has been lost. To whom, among others, this data brea...
data breachspecial categoriesunion membershipbreach reporting - Question #116Key concepts of data protection
According to the General Data Protection Regulation (GDPR), which category of personal data is considered to be sensitive data?
special categoriessensitive datatrade union membershipGDPR Article 9 - Question #117Data protection breaches
What is the term used in the General Data Protection Regulation (GDPR) for the disclosure of, or unauthorized access to, personal data?
data breachGDPR terminologyconfidentiality breachdefinitions - Question #118Privacy by Design and by Default
When is a Data Protection Impact Assessment (DPIA) under the General Data Protection Regulation (GDPR) mandatory?
DPIAmandatory assessmenthigh risk processingnew technologies - Question #120Data protection breaches
According to the GDPR, in what situation must data subjects always be notified of a personal data breach?
data breach notificationdata subject notificationhigh riskbreach obligations - Question #121Rights of the data subject
A person is moving from city A to city B, within an EEA member state. In city A he was a patient of the local hospital
data portabilityright to accessmedical recordsdata subject rights - Question #122Roles and responsibilities
A controller wants to outsource processing of personal data to a processor. What must be done before outsourcing?
controller-processor contractoutsourcingdata processing agreementGDPR Article 28 - Question #123Introduction to privacy and data protection
What is the legal status of the GDPR?
GDPR legal statusEEA regulationdirect applicabilitymember state derogations - Question #124International data transfers
data between the EEA and the US. The ruling is based on the data protection measures described in the EU-US Privacy Shield. What kind of a ruling is this?
adequacy decisionEU-US Privacy Shieldinternational transfersArticle 45 - Question #125Key concepts of data protection
What is the main use of a persistent cookie?
persistent cookiespersonalizationweb trackingcookies - Question #126Key concepts of data protection
In the GDPR, some types of personal data are regarded as special category personal dat
special category datapolitical opinionsArticle 9sensitive data - Question #127Key concepts of data protection
To plan the amount of parking space needed, a local government monitors and saves the license plate number of every car that enters and leaves the city center. They have obtained p...
storage limitationpurpose limitationdata principlesArticle 5 - Question #128Supervisory authorities and enforcement
binding contract with a processor in the Netherlands for the processing of personal data of data subjects with various nationalities. A personal data breach occurs. The supervisory...
lead supervisory authorityone-stop-shopmain establishmentcross-border processing - Question #129Supervisory authorities and enforcement
According to the GDPR, what is a task of a supervisory authority?
supervisory authority tasksGDPR enforcementmonitoring complianceArticle 57 - Question #130Privacy by Design and by Default
One of the seven principles of data protection by design is Functionality - Positive-Sum, not Zero- Sum. What is the essence of this principle?
Privacy by Designpositive-sumfunctionalityAnn Cavoukian principles - Question #131Supervisory authorities and enforcement
What is the purpose of a data protection audit by the supervisory authority?
data protection auditsupervisory authoritycompliance monitoringenforcement powers - Question #132Rights of the data subject
A company wishes to use personal data of their customers. They wish to start sending all female customers a customized newsletter. What right do all data subjects have in this scen...
right to objectprofilingdirect marketingArticle 21 - Question #133Key concepts of data protection
The GDPR refers to the principles of proportionality and subsidiarity. What is the meaning of subsidiarity in this context?
subsidiarityproportionalitydata minimizationGDPR principles - Question #134Key concepts of data protection
A shopkeeper wants to register how many visitors enter his shop every day. A system detects the MAC- address of each visitor's smartphone. It is impossible for the shopkeeper to id...
personal data definitionMAC addressindirect identificationrelativistic approach - Question #135Key concepts of data protection
Personal data shall be adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed. Which data processing principle is described he...
data minimizationArticle 5adequacydata principles - Question #136Privacy by Design and by Default
According to the GDPR, when is a data protection impact assessment (DPIA) obligatory?
DPIAhigh risk processingArticle 35risk assessment - Question #137Roles and responsibilities
Organizations are obliged to keep a number of records to demonstrate compliance with the GDPR. Which record is not obligatory according to the GDPR?
records of processingArticle 30ROPAdocumentation obligations - Question #139Introduction to privacy and data protection
The GDPR does not define privacy as a term but uses the concept implicitly throughout the text. What is a correct definition of privacy as implicitly used throughout the GDPR?
privacy definitionArticle 8 ECHRprivate lifefundamental rights - Question #140Rights of the data subject
Which data subject right is explicitly defined by the GDPR?
right of accessArticle 12free of chargedata subject rights - Question #141Privacy by Design and by Default
One of the objectives of a data protection impact assessment (DPIA) is to strengthen the confidence of customers or citizens in the way personal data is processed and privacy is re...
DPIAorganizational truststakeholder confidenceArticle 35 - Question #142Privacy by Design and by Default
What is a description of data protection by design and by default?
privacy by designdata protection by defaultArticle 25built-in privacy - Question #143Introduction to privacy and data protection
What is the relationship between data protection and privacy?
privacy vs data protectionfundamental conceptsdata protection measuresdefinitional distinction - Question #144Key concepts of data protection
A natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal dat
controller definitiondata controllerGDPR key termslegal person - Question #145Key concepts of data protection
The GDPR describes the principle of data minimization. How can organizations comply with this principle?
data minimizationGDPR principlespersonal data adequacynecessity principle - Question #146Key concepts of data protection
Some data processing falls outside of the material scope of the GDPR. What type of processing is not subject to the GDPR?
GDPR material scopehousehold exemptionpersonal use exemptionGDPR applicability - Question #147Data protection breaches
Which of the following has a data breach under the General Data Protection Regulation (GDPR)?
data breach identificationunauthorized accesssecurity incidentGDPR breach definition - Question #148Data protection breaches
Your credit card has been cloned. A card contains various personal information. What category of data breach is this incident?
data breach categoriesdigital breachcredit card cloningpersonal data breach types - Question #149Introduction to privacy and data protection
The General Data Protection Regulation (GDPR) is often known as the "European privacy law". What is the relationship between 'privacy' and 'data protection'?
privacy vs data protectionGDPR conceptsprivacy definitiondata protection purpose