Summer Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: buysanta

Exact2Pass Menu

Privacy and Data Protection Foundation

Last Update 3 hours ago Total Questions : 149

The Privacy and Data Protection Foundation content is now fully updated, with all current exam questions added 3 hours ago. Deciding to include PDPF practice exam questions in your study plan goes far beyond basic test preparation.

You'll find that our PDPF exam questions frequently feature detailed scenarios and practical problem-solving exercises that directly mirror industry challenges. Engaging with these PDPF sample sets allows you to effectively manage your time and pace yourself, giving you the ability to finish any Privacy and Data Protection Foundation practice test comfortably within the allotted time.

Question # 11

The General Data Protection Regulation (GDPR) is based on the principles of proportionality and subsidiarity.

What is the meaning of “proportionality” in this context?

A.

Personal data can be processed according to the use of requirements.

B.

Personal data cannot be reused without explicit and informed consent.

C.

Personal data can only be processed if there are no other means to achieve the purposes.

D.

Personal data must be adequate, relevant and not excessive in relation to the purposes.

Question # 12

A shopkeeper wants to register how many visitors enter his shop every day. A system detects the MAC- address of each visitor’s smartphone. It is impossible for the shopkeeper to identify the owner of the phone from this signal, but telephone providers can link the MAC-address to the owner of the phone. According to the GDPR, is the shopkeeper allowed to use this method?

A.

Yes, because the shopkeeper cannot identify the owner of the telephone

B.

No, because the telephone providers are the owners of the MAC-addresses.

C.

No, because the telephone’s MAC-address must be regarded as personal data.

D.

Yes, because the visitor has automatically consented by connecting to the Wi-Fi

Question # 13

Which organizations need to comply with the General Data Protection Regulation (GDPR)?

A.

Only organizations that have employees in the European Union (EU).

B.

Only organizations that have their headquarters in the European Union (EU).

C.

All organizations anywhere in the world.

D.

All organizations located in the European Union and also organizations outside the European Union that offer goods or services to data subjects in the EU.

Question # 14

After notifying the supervisory authority, what should be the first action the controller must take when it finds a security breach where unauthorized people have accessed personal data?

A.

Contact the DPO for formal notification to the Supervisory Authority.

B.

Analyze whether sensitive data has been accessed.

C.

Register a Police Report at the cybercrime station.

D.

Notify data subjects that have been subject to a security breach.

Question # 15

To comply with the General Data Protection Regulation (GDPR) it is necessary to create a procedure for reporting data breaches to the Supervisory Authority.

As the controller is a public administration agency, which option is a requirement for this procedure?

A.

It must contain a step to perform a Data Protection Impact Analysis (DPIA).

B.

It must include an audit step.

C.

It should include a step to consult the Data Protection Officer (DPO) in order to determine whether notification to the Supervisory Authority is necessary.

D.

It must contain a step to notify the data subject.

Question # 16

What is a responsibility of Supervisory Authorities in EEA countries?

A.

Research on security breaches of corporate information

B.

Supervision of all data processing operations controlled by a controller in an EEA country

C.

Supervision of all data processing operations where the data subjects are residents of an EEA country

Question # 17

A controller discovers that a data subject, who had given consent for the processing of his data, has passed away. What this implies for data processing according to the General Data Protection Regulation (GDPR)?

A.

With the death of the data owner, the controller can continue processing the data, as they are no longer under the GDPR.

B.

The data can only be processed by the controller respecting the consent provided by the holder.

C.

The controller must delete the data of the holder, since with the death of the holder the consent is automatically revoked.

D.

The controller can process the data of a deceased person as long as it anonymizes the data.

Question # 18

Subcontracting treatment is regulated by contract or other regulatory act under Union or Member State law, which links the processor to the controller.

What this contract or other regulatory act stipulates?

A.

A process for testing, assessing and regularly evaluating the effectiveness of technical and organizational measures to ensure safe treatment.

B.

The processor assists the driver through technical and organizational measures to enable it to fulfill its obligation to respond to requests from data subjects.

C.

The description of categories of data subjects and categories of personal data

D.

The purpose of data processing

Question # 19

One of the basic principles of the General Data Protection Regulation (GDPR) is subsidiarity.

What is subsidiarity to GDPR?

A.

Personal data can only be collected for explicit, legitimate and specific purposes and cannot be processed for any other purpose.

B.

Only the personal data needed to achieve a specific purpose should be collected.

C.

The least privacy-violating means should be used when processing personal data.

D.

Personal data must be kept for a period not longer than necessary.

Question # 20

According to the General Data Protection Regulation (GDPR), which category of personal data is considered to be sensitive data?

A.

Labor union association

B.

Passport number

C.

Credit card details

D.

Social security number

Go to page: