ANSWERS SURE A+
✔✔_________ is/are a key part of the equation when assessing risk.
-Controller obligatins
-Expected loss
-Purpose of processing
-Data subject rights - ✔✔Expected loss
✔✔Which of the following should be considered for a holistic approach to data security?
-A policy framework
-Information technology
-Incident detectoin and response
-All of the above - ✔✔All of the above
Additional considerations may include management, and worker buy-in, and the
physical environment.
✔✔__________must be included in a processor contract.
Check all that apply:
-the categories of data subjects
- the nature and purpose of the processing
-the subject matter and duration of the processing
-the type of personal data
-The method for destroying personal information following processing activities - ✔✔All
EXCEPT The method for destroying personal data.
Contract should also contain the obligations and rights of the controller
✔✔A processor is responsible for implementing appropriate technical and
organisational measures to keep personal data secure. True or false? - ✔✔True
✔✔A processor may process personal data only on documented instructions from the
controller. True or false? - ✔✔True
✔✔A controller must notify the supervisory authority of a personal data breach if
__________.
-A breach is likely to result in a risk to the rights and freedoms of natural persons
-A breach is likely to result in a high risk for the rights and freedoms of natural persons -
✔✔A breach likely to result in risk to the rights and freedoms of natural persons.
, ✔✔A controller must notify the data subjects of a personal data breach if the breach is
likely to result in a high risk to the rights and freedoms of those individuals
unless_________. Pick all that apply:
-Individual notice require disproportionate effort
-Prior implementation of appropriate technical
and organisational measures rendered the personal data unintelligible or encrypted
-Post-breach actions greatly reduce the risk to the rights and freedoms of the data
subjects. - ✔✔All
✔✔Which of the following data subject rights provides data subjects with entitlements to
certain information, obtainable from the controller upon request? Pick all that apply.
-right of access
-right of erasure
-right to object
-right to restriction of processing - ✔✔right of access
✔✔Right of access grants data subjects access to which of the following types of
information? Select all that apply.
-The means of data storage
-Retention periods
_The purpose of processing
-Locations where the date is being processed - ✔✔-The purpose of processing
-Retention periods
-Locations where the data is being processed
✔✔The right to be forgotten is part of what data subjectc right?
-Right to data portability
-Right to erasure
-Right to restriction of processing
-Right to rectification - ✔✔Right to erasure
✔✔Which of the following is not a method listed by the GDPR as a method for
restricting processing of personal data. Select all that apply.
-Noting the restriction in the system
-Moving the data to a separate system
-Temporarily blocking a website
-Disabling the data management system - ✔✔Disabling the data management system