New Year Special 60% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: bestdeal

Free Exin PDPF Practice Exam with Questions & Answers

Questions 1

The GDPR states that records of processing activities must be kept by the controller. To whom must the controller make these records available, if requested?

Options:
A.

The data processor

B.

The Data Protection Officer

C.

The European Commission

D.

The supervisory authority

Exin PDPF Premium Access
Questions 2

“The controller shall implement appropriate technical and organizational measures for ensuring that (…) only personal data which are necessary for each specific purpose of the processing are processed.”

Which term in the GDPR is defined here?

Options:
A.

Compliance

B.

Data protection by default and by design

C.

Embedded data protection

Questions 3

When a data breach occurs in a company that has branches in several countries of the European Union, which supervisory authority is competent to take the appropriate measures?

Options:
A.

The Supervisory Authority of the country where the company’s main establishment is located.

B.

The Supervisory Authority of the country where the subsidiary with the largest number of affected holders

is located.

C.

The Supervisory Authority of the country that had the most affected holders.

D.

The Supervisory Authority of the country where the company’s largest subsidiary is located.

Questions 4

In the GDPR, some types of personal data are regarded as special category personal data. Which personal data are considered special category personal data?

Options:
A.

An address list of members of a political party

B.

A genealogical register of someone’s ancestors

C.

A list of payments made using a credit card

Questions 5

What is the term used in the General Data Protection Regulation (GDPR) for the disclosure of, or unauthorized access to, personal data?

Options:
A.

Security incident

B.

Incident

C.

Breach of confidentiality

D.

Data breach

Questions 6

Which condition below allows personal data to be processed legally?

Options:
A.

A Data Privacy Impact Assessment (DPIA) should be performed prior to data collection.

B.

Data processing must be previously authorized by the Supervisory Authority.

C.

Holders’ rights must be protected by a privacy policy.

D.

There must be a legitimate basis for data processing.

Questions 7

According to the principle of purpose limitation, data should not be processed beyond the legitimate purpose defined. However, further processing is allowed in a few specific cases, provided that appropriate safeguards for the rights and freedoms of the data subjects are taken. For which purpose is further processing not allowed?

Options:
A.

For archiving purposes in the public interest

B.

For generalized statistical purposes

C.

For scientific or historical research purposes

D.

For direct marketing and commercial purposes

Questions 8

A person who works for a union took home a draft newsletter to finish it. The thumb drive containing the draft and contact list has been lost. To whom, among others, this data breach should be reported?

Options:
A.

To all members of the contact list

B.

To the Union staff

C.

To the police

Questions 9

Which of the options below best represents data protection by design?

Options:
A.

It aims to incorporate security measures to protect data from the moment it is collected, throughout the processing and until its destruction at the end of the process

B.

It aims to ensure that personal data is automatically part of a protection process.

C.

It aims to create privacy impact analysis procedures (DPIA), notifications of breaches of privacy and fulfil requests from data subjects.

Questions 10

GDPR quotes in one of its principles that personal data should be adequate, relevant and limited to what is necessary in relation to its purpose. What principle is this?

Options:
A.

integrity and confidentiality

B.

purpose limitation

C.

data minimization

D.

lawfulness, loyalty and transparency