Summer Special 60% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: bestdeal

Free Exin PDPF Practice Exam with Questions & Answers | Set: 2

Questions 11

The Supervisory Authority is notified whenever an organization intends to process personal data, except for some specific situations. The Supervisory Authority keeps a publicly accessible register of these data processing operations.

What else is a legal obligation of the Supervisory Authority in reaction to such a notification?

Options:
A.

To assess compliance with the law in all classes where sensitive personal data is processed

B.

To assess the legitimacy of operations that involve specific risks for the data subjects

C.

To assess the legitimacy of binding contract(s) between the controller and the data processor(s)

D.

To give out a license for the data processing, specifying the types of personal data which are allowed

Exin PDPF Premium Access
Questions 12

Organizations are obliged to keep a number of records to demonstrate compliance with the GDPR. Which record is not obligatory according to the GDPR?

Options:
A.

A record of notifications sent to the supervisory authority regarding processing of personal data

B.

A record of all intended processing together with the processing purpose(s) and legal justifications

C.

A record of processors including personal data provided and the period this data can be retained

D.

A record of data breaches with all relevant characteristics, including notifications

Questions 13

How does GDPR regulate this specific case?

A woman uses the services of a gym in the city where she lives. Yet she will move to another town. So, she requests the current gym to transfer all her data, exercises, eating plans, physical evaluations, etc. to another gym in the new town.

Options:
A.

The current gym is not obliged to answer the holder request, because this could jeopardize the secret of its business.

B.

The current gym should send all her data directly to the new gym.

C.

The gym of the new town should get in contact with the gym and request the data.

D.

The current gym should provide the data to her.

Questions 14

A personal data breach has occurred, and the controller is writing a draft notification for the supervisory authority. The following information is already in the notification:

-The nature of the personal data breach and its possible consequences.

-Information regarding the parties that can provide additional information about the data breach.

What other information must the controller provide?

Options:
A.

Information of local and national authorities that were informed about the data breach.

B.

Name and contact details of the data subjects whose data may have been breached

C.

Suggested measures to mitigate the adverse consequences of the data breach.

D.

The information needed to access the personal data that have been breached.

Questions 15

While performing a backup, a data server disk crashed. Both the data and the backup are lost. The disk contained personal data, but no special category personal data. The processor states that this is a personal data breach. Is the statement of the processor true?

Options:
A.

Yes, because there were no special category personal data stored on the disk.

B.

No, because no personal data on the disk were processed, only destroyed

C.

Yes, because the personal data on the disk were unlawfully processed.

D.

No, because this is only a security incident and not a data breach

Questions 16

A person finds that a private videotape showing her in a very intimate situation has been published on a website. She never consented to publication and demands that the video is being removed without undue delay.

According to the GDPR, what should be done next?

Options:
A.

Nothing. The video may be regarded as ‘news’ and, therefore, the website is only exercising its right to freedom of expression and information.

B.

The controller erases the video from the website and, when possible, informs any controller who might

process the same video, that it must be erased.

C.

The controller erases the video from the website. There is no obligation however, to inform others who might have copied it, that it should be erased.

D.

The controller directs the person to seek a lawyer and informs that he cannot exclude before a juridical authorization.

Questions 17

A written contract between a controller and a processor is called a data processing agreement. According to

the GDPR, what does not have to be covered in the written contract?

Options:
A.

The contractor code of business ethics and conduct that is used.

B.

Which data are covered by the data processing agreement

C.

The information security and personal data breach procedures

D.

The technical and organizational measures implemented

Questions 18

One of the objectives of a data protection impact assessment (DPIA) is to strengthen the confidence of customers or citizens in the way personal data is processed and privacy is respected. How can a DPIA strengthen the confidence?

Options:
A.

The organization proves that it takes privacy seriously and aims for compliance with the GDPR.

B.

The organization minimizes the risk of costly adjustments in processes or the redesign of systems in a later stage.

C.

The organization prevents non-compliance with the GDPR and minimizes the risk of fines

Questions 19

A controller asks a processor to produce a report containing customers who have purchased a particular product more than once in the past 6 months.

The processor provides services to several companies (which in this case are the controllers).

When generating the requested report, it uses customer data collected by another controller, that is, for a different purpose.

Fortunately, the error is noticed in time, the report is not sent, and nobody has had access to this data. In this case, how does the processor need to proceed and what action should the controller take?

Options:
A.

The processor notifies the Supervisory Authority that a violation has occurred. The controller will be notified and must perform a Data Protection Impact Assessment (DPIA).

B.

The processor needs to notify the controller. And the controller can assess whether there were risks to the data subjects.

C.

The processor needs to notify the controller so that the controller notifies the Supervisory Authority of the personal data breach.

D.

As the error was noticed in time and the report was not sent, there is no need for the processor to inform the controller. The processor must delete the wrong report and generate a new one, this time with the correct data.

Questions 20

In its Article 9 the GDPR categorizes some types of personal data as “sensitive”.

Of these below which are considered sensitive?

Options:
A.

Date of birth of a person.

B.

A person’s home address.

C.

Soccer team that a person supports.

D.

Result of a medical examination.