Summer Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: buysanta

Exact2Pass Menu

Privacy and Data Protection Foundation

Last Update 3 hours ago Total Questions : 149

The Privacy and Data Protection Foundation content is now fully updated, with all current exam questions added 3 hours ago. Deciding to include PDPF practice exam questions in your study plan goes far beyond basic test preparation.

You'll find that our PDPF exam questions frequently feature detailed scenarios and practical problem-solving exercises that directly mirror industry challenges. Engaging with these PDPF sample sets allows you to effectively manage your time and pace yourself, giving you the ability to finish any Privacy and Data Protection Foundation practice test comfortably within the allotted time.

Question # 21

What is the purpose of Data Lifecycle Management (DLM)?

A.

Ensure data integrity and its periodic update

B.

Ensure data confidentiality and availability throughout its useful life.

C.

Ensure that the processing of personal data, throughout its useful life complies with the GDPR

D.

Ensure data confidentiality throughout its useful life, from collection to deletion.

Question # 22

How should data protection between the processor and controller be regulated in accordance with the General Data Protection Regulation (GDPR)?

A.

Contract

B.

Supervisory Authority endorsement.

C.

Compulsory Corporate Rules.

D.

Standard contractual clauses.

Question # 23

The General Data Protection Regulation (GDPR) is related to the protection of personal data. What is the definition of personal data?

A.

Preservation of confidentiality, integrity and availability of information

B.

Any information regarding an identified or identifiable natural person

C.

Any information that European citizens want to protect

D.

Data that directly or indirectly reveals racial or ethnic origins, someone’s religious views, and their data related to sexual health and habits

Question # 24

The word privacy is never mentioned in the General Data Protection Regulation (GDPR) text.

Despite this, what would be the best definition of the privacy according to the Regulation?

A.

The right not to have your life monitored by technologies.

B.

Have freedom of expression.

C.

The right to respect for private and family life, for home and communications.

D.

The right to have your personal data protected.

Question # 25

A German company wants to enter into a binding contract with a processor in the Netherlands for the processing of sensitive personal data of German data subjects. The Dutch Supervisory Authority is informed of the type of data and the aims of the processing, including the contract describing what data will be processed and what data protection procedures and practices will be in place.

According to the GDPR, what should the Dutch Supervisory Authority do in this scenario?

A.

Report the data processing to the German Supervisory Authority and leave the supervising to them.

B.

Supervise the processing of personal data in accordance with Dutch Law.

C.

Supervise the processing of personal data in accordance with German Law.

D.

The Dutch Supervisory Authority should check that adequate binding contracts are in place. The German Supervisory Authority should supervise.

Question # 26

A person who works for a union took home a draft newsletter to finish it. The thumb drive containing the draft and contact list has been lost. To whom, among others, this data breach should be reported?

A.

To all members of the contact list

B.

To the Union staff

C.

To the police

Question # 27

A security breach has occurred in an information system that also holds personal data. According to the GDPR, what is the very first thing the controller must do?

A.

Assess the risk of adverse effects to the data subjects using a data protection impact assessment (DPIA)

B.

Ascertain whether the breach may have resulted in loss or unlawful processing of personal data

C.

Report the breach immediately to all data subjects and the relevant supervisory authority

D.

Assess whether personal data of a sensitive nature has or may have been unlawfully processed

Question # 28

What is the main purpose of the General Data Protection Regulation (GDPR)?

A.

Protecting the data of everyone in Europe.

B.

Protect the data of everyone in the world.

C.

Protect data of data subjects located in the European Economic Area (EEA), regardless of the country of processing.

D.

Protect confidential business data.

Question # 29

Which of the following has a data breach under the General Data Protection Regulation (GDPR)?

A.

A processor, after terminating its contract with the controller, deletes personal data.

B.

A collaborator goes away without locking his workstation.

C.

A backup is restored by the controller to a corrupted personal data server.

D.

A notebook with financial reports from a multinational is stolen.

Question # 30

A company located in France wishes to enter into a compulsory contract with a processor located in Portugal. This contract aims to process sensitive French personal data. The Portuguese Supervisory Authority is informed about this contract and the type of processing.

How should Portuguese Supervisory Authority proceed, in accordance with the General Data Protection Regulation (GDPR)?

A.

Supervise the processing of personal data according to the guidelines of the Supervisory Authority of Portugal.

B.

Report the data processing to the French Supervisory Authority, which must take over the supervision.

C.

Verify that adequate compulsory contracts have been established and leave supervision to the French Supervisory Authority.

D.

Supervise the processing of personal data in accordance with the French Supervisory Authority legislation.

Go to page: