Weekend Special 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: sale65best

Free Exin PDPF Practice Exam with Questions & Answers | Set: 4

Questions 31

According to the GDPR, when is a data protection impact assessment (DPIA) obligatory?

Options:
A.

When a project includes technologies or processes that use personal data

B.

When processing is likely to result in a high risk to the rights of data subjects

C.

When similar processing operations with comparable risks are repeated

Exin PDPF Premium Access
Questions 32

On July 12, 2016 the European Commission implemented a ruling regarding the transfer of personal data between the EEA and the US. The ruling is based on the data protection measures described in the EU-US Privacy Shield. What kind of a ruling is this?

Options:
A.

Derogation

B.

Legally binding contract

C.

Treaty superseding the GDPR

D.

Adequacy decision

Questions 33

Which of these options is an example of a data breach?

Options:
A.

Transfer of personal data outside the EU

B.

Loss of personal data

C.

A security incident related to corporate data.

Questions 34

In the contract between the controller and processor for the processing of personal data, which of the options below represents the sole responsibility of the Controller?

Options:
A.

Erase all personal data after the completion of treatment-related services, deleting existing copies.

B.

Treat personal data only through documented instructions, including with regard to data transfers to third countries or international organizations.

C.

Ensure that the persons authorized to process personal data have made a commitment to confidentiality.

D.

Apply technical and organizational measures to ensure that only personal data that are necessary for each specific purpose of processing are processed.

Questions 35

A German company wants to enter into a binding contract with a processor in the Netherlands for the processing of sensitive personal data of German data subjects. The Dutch Supervisory Authority is informed of the type of data and the aims of the processing, including the contract describing what data will be processed and what data protection procedures and practices will be in place.

According to the GDPR, what should the Dutch Supervisory Authority do in this scenario?

Options:
A.

Report the data processing to the German Supervisory Authority and leave the supervising to them.

B.

Supervise the processing of personal data in accordance with Dutch Law.

C.

Supervise the processing of personal data in accordance with German Law.

D.

The Dutch Supervisory Authority should check that adequate binding contracts are in place. The German Supervisory Authority should supervise.

Questions 36

Who is responsible for demonstrating the compliance of personal data processing with the General Data Protection Regulation (GDPR)?

Options:
A.

The Data Protection Officer (DPO)

B.

The processor

C.

The controller

D.

The supervisory authority

Questions 37

A good practice is to lock the computer automatically or manually when you are away from the workstation.

The company’s DPO realizes that this procedure is not being followed by employees. This occurrence should be classified in which category?

Options:
A.

Classified as a security vulnerability

B.

Classified as a security incident

C.

There is no specific category.

D.

Classified as a data breach

Questions 38

A controller discovers that a data subject, who had given consent for the processing of his data, has passed away. What this implies for data processing according to the General Data Protection Regulation (GDPR)?

Options:
A.

With the death of the data owner, the controller can continue processing the data, as they are no longer under the GDPR.

B.

The data can only be processed by the controller respecting the consent provided by the holder.

C.

The controller must delete the data of the holder, since with the death of the holder the consent is automatically revoked.

D.

The controller can process the data of a deceased person as long as it anonymizes the data.

Questions 39

According to the GDPR, in what situation must data subjects always be notified of a personal data breach?

Options:
A.

When personal data is processed at a facility of the processor that is not located within the borders of the EEA

B.

When personal data is processed by a party that agreed to the draft processing contract but has not yet signed it

C.

When the system on which the personal data is processed is attacked causing damage to its storage devices

D.

When there is a significant probability that the breach will lead to a high risk for the privacy of the data subjects

Questions 40

Which of these should appear in a Data Protection Impact Assessment (DPIA) according to the General Data Protection Regulation (GDPR)?

Options:
A.

An assessment of the need and proportionality of treatment operations in relation to the objectives.

B.

Data Protection Officer (DPO) contact and responsibilities.

C.

An inventory and the flow of personal data within the organization.

D.

A survey of other laws that must be taken into account in addition to the GDPR.