WGU D320 ALL TEST PAPER QUESTIONS AND
ANSWERS SURE A+
✔✔GDPR — Right to Rectification - ✔✔Data subjects have the right to request
corrections to inaccurate information collected about them.
✔✔GDPR — Right to Data Portability - ✔✔Data subjects have the right to receive their
data in machine-readable format so it can be used by other systems.
✔✔GDPR — Right to Object - ✔✔Data subjects can object to processing they believe is
out of compliance with GDPR or opt out of direct marketing.
✔✔GDPR — Right to Restriction of Processing - ✔✔Data subjects can request
controllers halt processing activities without requesting full erasure.
✔✔GDPR — Automated Decision-Making - ✔✔AI or automated processing alone
cannot make decisions with significant legal impact on a person.
✔✔GDPR — Adequacy Decision - ✔✔EU ruling that another country's privacy laws are
sufficient to allow data transfers without additional mechanisms. US does NOT have an
adequacy decision.
✔✔GDPR — Binding Corporate Rules (BCRs) - ✔✔Complex agreements where a
corporate group commits to GDPR-level data protection across all jurisdictions.
Requires EU supervisory authority approval.
✔✔GDPR — Standard Contractual Clauses (SCCs) - ✔✔Contract language approved
by the European Commission obligating non-EU companies to follow GDPR practices.
Simpler alternative to BCRs.
, ✔✔GDPR — Privacy Shield / Schrems II - ✔✔Former US-EU data transfer framework
struck down in July 2020 (Schrems II ruling by CJEU). BCRs and SCCs remain as
alternatives.
✔✔GDPR — Derogations - ✔✔Limited circumstances allowing data transfer to non-EU
entities without adequacy decision, BCRs, or SCCs. Includes consent, contractual
necessity, public interest, legal obligations.
✔✔GDPR Principle 1 — Lawfulness, Fairness, Transparency - ✔✔Data must be
processed lawfully, fairly, and transparently to the data subject.
✔✔GDPR Principle 2 — Purpose Limitation - ✔✔Data collected for specified, explicit,
legitimate purposes only. Cannot be repurposed without consent.
✔✔GDPR Principle 3 — Data Minimization - ✔✔Only collect what is adequate, relevant,
and strictly necessary.
✔✔GDPR Principle 4 — Accuracy - ✔✔Personal data must be accurate and kept up to
date.
✔✔GDPR Principle 5 — Storage Limitation - ✔✔Not kept in identifiable form longer than
necessary.
✔✔GDPR Principle 6 — Integrity and Confidentiality - ✔✔Processed securely with
appropriate technical and organizational measures.
✔✔GDPR Principle 7 — Accountability - ✔✔Data controller must demonstrate
compliance with all other principles.
✔✔GAPP (Generally Accepted Privacy Principles) - ✔✔Global privacy management
framework by AICPA and CICA. 10 principles. Note: GAPP = privacy. GAAP =
accounting. Don't confuse them.
✔✔GAPP — 10 Principles - ✔✔1. Management, 2. Notice, 3. Choice & Consent, 4.
Collection, 5. Use/Retention/Disposal, 6. Access, 7. Disclosure to Third Parties, 8.
Security for Privacy, 9. Quality, 10. Monitoring & Enforcement
✔✔GAPP vs GAAP - ✔✔Both published by AICPA/CICA. GAPP = Generally Accepted
PRIVACY Principles. GAAP = Generally Accepted ACCOUNTING Practices. Common
exam trick.
✔✔ISO/IEC 27001 - ✔✔Foundational ISMS (Information Security Management System)
standard. Most globally recognized security program certification. Platform/product
agnostic.
ANSWERS SURE A+
✔✔GDPR — Right to Rectification - ✔✔Data subjects have the right to request
corrections to inaccurate information collected about them.
✔✔GDPR — Right to Data Portability - ✔✔Data subjects have the right to receive their
data in machine-readable format so it can be used by other systems.
✔✔GDPR — Right to Object - ✔✔Data subjects can object to processing they believe is
out of compliance with GDPR or opt out of direct marketing.
✔✔GDPR — Right to Restriction of Processing - ✔✔Data subjects can request
controllers halt processing activities without requesting full erasure.
✔✔GDPR — Automated Decision-Making - ✔✔AI or automated processing alone
cannot make decisions with significant legal impact on a person.
✔✔GDPR — Adequacy Decision - ✔✔EU ruling that another country's privacy laws are
sufficient to allow data transfers without additional mechanisms. US does NOT have an
adequacy decision.
✔✔GDPR — Binding Corporate Rules (BCRs) - ✔✔Complex agreements where a
corporate group commits to GDPR-level data protection across all jurisdictions.
Requires EU supervisory authority approval.
✔✔GDPR — Standard Contractual Clauses (SCCs) - ✔✔Contract language approved
by the European Commission obligating non-EU companies to follow GDPR practices.
Simpler alternative to BCRs.
, ✔✔GDPR — Privacy Shield / Schrems II - ✔✔Former US-EU data transfer framework
struck down in July 2020 (Schrems II ruling by CJEU). BCRs and SCCs remain as
alternatives.
✔✔GDPR — Derogations - ✔✔Limited circumstances allowing data transfer to non-EU
entities without adequacy decision, BCRs, or SCCs. Includes consent, contractual
necessity, public interest, legal obligations.
✔✔GDPR Principle 1 — Lawfulness, Fairness, Transparency - ✔✔Data must be
processed lawfully, fairly, and transparently to the data subject.
✔✔GDPR Principle 2 — Purpose Limitation - ✔✔Data collected for specified, explicit,
legitimate purposes only. Cannot be repurposed without consent.
✔✔GDPR Principle 3 — Data Minimization - ✔✔Only collect what is adequate, relevant,
and strictly necessary.
✔✔GDPR Principle 4 — Accuracy - ✔✔Personal data must be accurate and kept up to
date.
✔✔GDPR Principle 5 — Storage Limitation - ✔✔Not kept in identifiable form longer than
necessary.
✔✔GDPR Principle 6 — Integrity and Confidentiality - ✔✔Processed securely with
appropriate technical and organizational measures.
✔✔GDPR Principle 7 — Accountability - ✔✔Data controller must demonstrate
compliance with all other principles.
✔✔GAPP (Generally Accepted Privacy Principles) - ✔✔Global privacy management
framework by AICPA and CICA. 10 principles. Note: GAPP = privacy. GAAP =
accounting. Don't confuse them.
✔✔GAPP — 10 Principles - ✔✔1. Management, 2. Notice, 3. Choice & Consent, 4.
Collection, 5. Use/Retention/Disposal, 6. Access, 7. Disclosure to Third Parties, 8.
Security for Privacy, 9. Quality, 10. Monitoring & Enforcement
✔✔GAPP vs GAAP - ✔✔Both published by AICPA/CICA. GAPP = Generally Accepted
PRIVACY Principles. GAAP = Generally Accepted ACCOUNTING Practices. Common
exam trick.
✔✔ISO/IEC 27001 - ✔✔Foundational ISMS (Information Security Management System)
standard. Most globally recognized security program certification. Platform/product
agnostic.