One of the objectives of a data protection impact assessment (DPIA) is to strengthen the confidence of customers or citizens in the way personal data is processed and privacy is respected. How can a DPIA strengthen the confidence?
The GDPR describes the principle of data minimization. How can organizations comply with this principle?
Regarding the Supervisory Authority’s “Investigative Powers”, it is correct to state:
A breach of security that leads to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored or otherwise processed. What is the exact term that is associated with this definition in the GDPR?
According to the GDPR, what is a mandatory topic in a DPIA report?
A secretary at a pediatric cardiology clinic instead of sending the doctor the list of patients scheduled for the day, sends it to all those responsible registered for the children with scheduled appointments.
According to the GDPR, does the Supervisory Authority need to be notified? And those responsible for the data holders?
What is the definition of privacy related to the General Data protection Regulation (GDPR)?
Which cause is a data breach according to the GDPR?
Which of the options below is classified as a personal data breach under the GDPR?
What is the legal status of the GDPR?
A person buys a product at a store located in the European Economic Area (EEA). At the time of purchase, you are asked to fill out a registration form and he informs his personal email.
As is usual in many stores, in the next few days this person will start receiving several marketing emails. He considers the frequency of these emails to be very high. Demanding his rights, he asks the store to delete all his personal data.
What the store must do according to the General Data Protection Regulation (GDPR)?
While paying with a credit card, the card is skimmed (i.e. the data on the magnetic strip is stolen). The magnetic strip contains the account number, expiration date, cardholder’s name and address, PIN number and more.
What kind of a data breach is this?
A company located in France wishes to enter into a compulsory contract with a processor located in Portugal. This contract aims to process sensitive French personal data. The Portuguese Supervisory Authority is informed about this contract and the type of processing.
How should Portuguese Supervisory Authority proceed, in accordance with the General Data Protection Regulation (GDPR)?
Which of the following options describes the concept of data minimization?
The GDPR contains several items. Which of these contains mandatory requirements?
According to the GDPR, what is the main reason to consider data protection in the initial design phase?
In its Article 9 the GDPR categorizes some types of personal data as “sensitive”.
Of these below which are considered sensitive?
A controller wants to switch processors. What is necessary to review before making this change, so that it remains GDPR compliant?
What is considered a personal data processing for the General Data Protection Regulation (GDPR)?
To plan the amount of parking space needed, a local government monitors and saves the license plate number of every car that enters and leaves the city center. They have obtained permission to collect data on the number of cars present in the city center. By comparing the license plate time of entry and exit the number of cars present every moment of each day is calculated. Each month a report is created detailing the average number of cars in the city center at specific moments for every day of the week. At every entrance to the city center, a billboard clearly states what data is collected by whom, the purpose of the processing and the fact that the license plate numbers are saved securely for up to two years, because the measurements will be repeated next year. Which of the basic principles for legitimate processing of personal data is violated in this scenario?
How does a Supervisory Authority collaborate to the application of GDPR?
Which of the following has a data breach under the General Data Protection Regulation (GDPR)?