Tested Questions Reviewed And
Revised With Correct Answers
Already Passed!!
1. What is profiling?
-the processing of personal data gathered from social media sites
-a form of automated decision making
-The act of enabling cookies
-All of the above - ANSWER A form of automated decision making
2. True or false. Both controllers and processors have accountability
obligations under GDPR. - ANSWER True
3. True or false: Data protection by design begins prior to processing and
incorporates data protection considerations into the planning phase. -
ANSWER True
4. What are the main values of data protection impact assessment (DPIA)?
Select all that apply.
-Demonstrating compliance to supervisory authorities
-Incorporating data protection consideration into organisational planning
-Determining the purpose of processing personal data - ANSWER -
Demonstrating compliance to supervisory authorities
,-Incorporating data protection considerations into organisational planning
5. True or false: The GDPR requires controllers to always contact the
supervisory authority following a DPIA and before processing. - ANSWER
False
6. True or false: The GDPR requires a data protection policy to be used where
proportionate in relation to processing activities. - ANSWER True
7. Which of the following must be included in controllers personal data
processing records, but not in the processors' records?
-International data transfers being made and the measures put in place to ensure
they are lawful
-purpose of processing
- general description of technical and organisational security measures that have
been implemented - ANSWER purpose of processing
8. True or false. The data protection officer must be an expert in data
protection law and practices. - ANSWER True
9. Which of the following are circumstances that require an organisation to
appoint a DPO? Select all that apply.
-The core activities of the controller or processor include regular and systematic
monitoring of data subjects on a large scale.
,-The core activities of the controller or processor consist of large scale processing
of special categories of data.
- The controller is a public authority. - ANSWER All
10. In what order should the following options for cross-border data transfers be
considered?
-Adequacy decisions
-Appropriate Safeguards
-Derogations - ANSWER -Adequacy decisons
-Appropriate Safeguards
-Derogations
11. Which of the following options for cross-border data transfers is a
determination by the European Commission that a third country has achieved an
EU-level of personal data protection.
-Adequacy decision
-Appropriate safeguard
-Derogation - ANSWER Adequacy decisions
12. Which of the followig countries hav ebeen deemed adequate by the
European Commission? Select all that apply.
Argentina
Uruguay
New Zealand
Switzerland - ANSWER All
, 13. Which of the following are EU-US Privacy Shield requirements? Select all that
apply.
-Publicly disclose the organisation's privacy policy
-Implement the Privacy Shield Principles
-Update the organization's privacy Policy annually.
-Publicize the commitment to the U.S. Department of Commerce to adhere to the
Privacy Shield Principles - ANSWER -Publicly disclose Privacy Policy
-Implement Privacy Shield Principles
-Publicize the commitment to the DoC
14. Which of the following are appropriate safeguards for cross-boarder data
transfers? Select all that apply.
-Public Interest
-Binding corporate rules
-Approved codes of conduct or certification mechanisms
-standard contractual clauses - ANSWER BCR
Codes of conduct/certification
standard clasues
15. Which appropriate safeguards allow large multinational companies to adopt a
policy suite with rules for handling personal data?