Complete Real Exam Questions And Correct Answers (Verified
Answers) Already Graded A+ | Guaranteed Success!! | Newest
Exam | Just Released!!
Which of the following was the first to implement national law
for data protection
in
1973?
(A). France
(B). Sweden
(C). Germany
(D). United Kingdom - ANSWER -(B). Sweden
In 2016's Guidance, the United Kingdom's Information
Commissioner's Office
(ICO)
reaffirmed the importance of using a "layered notice" to
provide data subjects
with
what?
(A). A privacy notice containing brief information whilst offering
access to further detail.
(B). A privacy notice explaining the consequences for opting
out of the use of cookies on a website.
(C). An explanation of the security measures used when
personal data is transferred to a third party.
,(D). An efficient means of providing written consent in
member states where they are required to do so. - ANSWER -
A). A privacy notice containing brief information whilst
offering access to further detail.
The European Parliament jointly exercises legislative and
budgetary functions with which of the following?
(A). The European Commission.
(B). The Article 29 Working Party.
(C). The Council of the European Union.
(D). The European Data Protection Board. - ANSWER -(C). The
Council of the European Union.
A company is located in a country NOT considered by the
European Union (EU) to have an adequate level of data
protection. Which of the following is an obligation of the
company if it imports
personal data from another organization in the European
Economic Area (EEA) under standard contractual clauses?
(A). Submit the contract to its own government authority.
(B). Ensure that notice is given to and consent is obtained from
data subjects. (C). Supply any information requested by a data
protection authority (DPA) within 30 days.
(D). Ensure that local laws do not impede the company from
meeting its contractual obligations. - ANSWER -A). Submit the
contract to its own government authority.
,In which of the following cases, cited as an example by a
WP29 guidance,
would
conducting
a single data protection impact assessment to address
multiple processing
operations be
allowed?
(A). A medical organization that wants to begin genetic testing
to support earlier research for which they have performed a
DPIA.
(B). A data controller who plans to use a new technology
product that has already undergone a DPIA by the
product's provider.
(C). A marketing team that wants to collect mailing addresses
of customers for whom they already have email addresses.
(D). A railway operator who plans to evaluate the same video
surveillance in all the train stations of his company. - ANSWER
-D). A railway operator who plans to evaluate the same video
surveillance in all the train stations of his company.
Select the answer below that accurately completes
the following:
"The right to compensation and liability under
the GDPR...
(A). ...provides for an exemption from liability if the data
controller (or data processor) proves that it
, is not in any way responsible for the event giving rise to the
damage."
(B). ...precludes any subsequent recourse proceedings against
other controllers or processors
involved in the same processing."
(C). ...can only be exercised against the data controller,
even if a data processor was involved in the same
processing."
(D). ...is limited to a maximum amount of EUR 20 million per
event of damage or loss." - ANSWER -(B). ...precludes any
subsequent recourse proceedings against other controllers or
processors involved in the same processing."
What was the aim of the European Data Protection Directive
95/46/EC?
(A). To harmonize the implementation of the European
Convention of Human Rights across all member states.
(B). To implement the OECD Guidelines on the Protection of
Privacy and transborder flows of Personal Data.
(C). To completely prevent the transfer of personal data out of
the European Union.
(D). To further reconcile the protection of the fundamental
rights of individuals with the free flow of
data from one member state to another. - ANSWER -B). To
implement the
OECD Guidelines on the Protection of Privacy and trans-border
flows of
Personal Data