Questions Reviewed And Revised
With Correct Answers
Already Passed!!
1. Data Processing
This refers to any operation or set of operations performed on personal data,
such as collection, storage, retrieval, modification, or deletion.
It encompasses both automated and manual activities, and under the GDPR, it
must comply with strict legal requirements to ensure the protection of
individuals' privacy and rights.
2. Data Processor
This refers to an entity or individual that processes personal data on behalf of a
data controller.
It acts under the instructions of the controller and handles tasks such as storing,
organizing, or retrieving data, without having ownership or control over the data
itself. It is subject to specific obligations under the GDPR.
3. Data Protection Authority (EU specific)
This is an independent public authority responsible for overseeing the
enforcement of data protection laws, such as the GDPR, within an EU member
state.
It monitors compliance, handles complaints, conducts investigations, and can
impose penalties for violations. Each member state has its own authority, which
also cooperates with others across the EU.
4. Data Protection by Default
,This principle requires that organizations implement privacy settings that
automatically prioritize data protection. By default, only the minimum necessary
personal data is collected, used, or shared, ensuring that privacy is maintained
without requiring user intervention.
It is part of the GDPR's broader mandate to safeguard personal data throughout
its lifecycle.
5. Data Protection by Design
This principle mandates that data protection measures be integrated into the
development and design of systems, products, and services from the outset.
Organizations must proactively embed privacy safeguards throughout the entire
data lifecycle, ensuring compliance with data protection laws like the GDPR and
minimizing risks to individuals' personal information.
6. Data Protection Commissioner (DPC)
This official is the head of an independent authority responsible for enforcing data
protection laws within a specific jurisdiction, such as an EU member state.
The Commissioner oversees compliance, investigates data breaches, handles
complaints, and ensures individuals' rights are protected under laws like the
GDPR.
7. Data Protection Directive (95/46/EC)
This was the EU law that governed the processing of personal data before the
GDPR. It set out rules for data protection and privacy across EU member states,
requiring them to implement national laws.
It aimed to protect individuals' privacy and ensure free movement of personal
data within the EU. It was replaced by the GDPR in 2018.
8. Data Protection Impact Assessment (DPIA)
This is a process used to identify and minimize the privacy risks of data processing
activities.
,Required under the GDPR for high-risk data processing, it helps organizations
assess how personal data is handled, the potential impact on individuals' rights,
and the necessary measures to mitigate risks, ensuring compliance with data
protection laws.
9. Data Protection Officer (DPO)
This individual is responsible for overseeing an organization's data protection
strategy and ensuring compliance with regulations like the GDPR.
The role includes monitoring data processing activities, advising on privacy
obligations, conducting audits, and serving as a point of contact for both
regulatory authorities and individuals regarding data privacy issues.
10. Data Protection Policy
This document outlines an organization's approach to handling personal data,
detailing the procedures, rules, and measures in place to ensure compliance with
data protection laws like the GDPR.
It covers areas such as data collection, processing, storage, and security, aiming to
protect individuals' privacy and safeguard their information.
11. Data Protection Principles
Article 5 of the GDPR lists the principles as such: Lawfulness, fairness and
transparency; Purpose limitation; Data minimisation; Accuracy; Storage limitation;
Integrity and confidentiality.
12. Data Quality (EU specific)
This data protection principle, explicitly stated in the GDPR, notes that personal
data should be relevant to the purposes for which it is to be used, and, to the
extent necessary for those purposes, should be accurate, complete and kept up-
to-date.
13. Data Recipient
, A natural or legal person, public authority, agency or another body, to which
personal data is disclosed, whether a third party or not.
14. Data Retention Directive
This former EU directive required telecommunications and internet service
providers to store metadata, such as call logs and IP addresses, for a set period.
Its aim was to assist law enforcement in investigating serious crimes. However, it
was invalidated by the CJEU in 2014 due to concerns over privacy and data
protection.
15. Data Subject
This term refers to any individual whose personal data is collected, processed, or
stored by an organization.
Under certain laws - including the GDPR - individuals have specific rights over
their data, including the right to access, correct, delete, and control how their
information is used.
16. De-identification
This process involves removing or altering personal data elements so that an
individual can no longer be directly or indirectly identified.
It is used to protect privacy, ensuring that the data cannot be linked back to a
specific person without additional information, commonly applied in research,
analytics, and privacy-preserving data processing.
17. Derogation
This refers to an exemption or relaxation of specific legal requirements under
certain circumstances.
In privacy law, it allows for exceptions to rules, such as data protection
regulations, under limited conditions, often to balance other legal obligations or
public interests while still safeguarding fundamental rights.
18. Direct Marketing (EU specific)