Spring Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: pass65

PDP9 BCS Practitioner Certificate in Data Protection Questions and Answers

Questions 4

When were data protection rights first introduced into UK law'?

Options:

A.

2000 (Data Protection Act 1998)

B.

1992 (Data Protection Act 1992).

C.

1984 (Data Protection Act 1984).

D.

2018 (Data Protection Act 2018)

Buy Now
Questions 5

Where a processor engages another processor ("sub-processor") to carry out processing activities on behalf of a controller, which of the following statements is CORRECT?

Options:

A.

The processor must receive prior written authorisation to use the sub-processor

B.

The processor may use the sub-processor without the written authorisation of the controller if it adheres to an approved code of conduct

C.

The processor may use the sub-processor without the written authorisation of the controller if the sub-processor signs a contract which reflects the same obligations as the contract with the controller

D.

The processor may use the sub-processor without the written authorisation of the controller if the processing is deemed to be low risk.

Buy Now
Questions 6

How are data sharing practices governed by data protection law?

Options:

A.

Data sharing practices are covered in the DPA 2018, supported by a statutory Code of Practice that provides specific guidance

B.

Data sharing practices are subject to the PECR until the new statutory Code of Practice is published

C.

Data sharing practices are covered by the Freedom of Information Act

D.

Data sharing practices are not specifically regulated, however the ICO provide best practice guidance

Buy Now
Questions 7

An investigation reveals that an individual is defrauding a public authority After a (suspected) tip off from a senior manager, the individual submits a Subject Access Request to the authority asking for a copy of all personal data relating to any investigations that have been carried out

What would be the BEST approach?

Options:

A.

The legal and professional privilege exemption applies to this information, and therefore the information does not need to be disclosed

B.

They do not need to disclose details of the investigation as they can rely on the crime and taxation exemption on the basis that disclosure would prejudice the investigation

C.

This is criminal offence data and therefore under the provisions of the Data Protection Act 2018, there is no obligation to disclose

D.

While the right to inform does not apply in relation to criminal acts, they need to disclose the information as this has not yet been passed to the police.

Buy Now
Questions 8

Which of the following is NOT a key requirement of independent supervisory authorities?

Options:

A.

Their leadership must change every four years

B.

They must operate independently.

C.

They review DPIAs in cases of unmitigated high risk

D.

They must provide each other with mutual assistance

Buy Now
Questions 9

If a complainant disagrees with the decision of the UK's supervisory authority, how do they appeal this decision?

Options:

A.

To the First Tier Tribunal (Information Rights)

B.

To the Information Commissioner

C.

To the European Data Protection Supervisor.

D.

To the European Commission

Buy Now
Questions 10

A privacy notice MUST NOT contain

Options:

A.

The contact details of the controller

B.

The purpose of the processing

C.

Details of the processor's staff

D.

Details of the right to lodge a complaint with the supervisory authority

Buy Now
Questions 11

What is the meaning of storage limitation in relation to UK GDPR Article 5 (1 )(e)?

Options:

A.

Keeping identifiable personal data for no longer than is necessary for the intended processing

B.

Storing data in a secure format only permitting access to those with a business need

C.

Only storing data in locations within the EU. except where there is an adequacy decision.

D.

Limiting the number of records stored in any single repository to minimise risk surface.

Buy Now
Questions 12

Two businesses decide to work together to sell their products by mail order Orders are made via a single online website and they each use their existing employees to administer and update each other's orders on a single order system regardless of product.

Which of the below is CORRECT of the roles of the two businesses in relation to the single order system'?

Options:

A.

They are controllers of their own information contained in the single order system only

B.

They are controllers of their own information in the single order system and processors of the information they process on behalf of the other business.

C.

The businesses are controllers of their respective information, and the staff are processors of this information

D.

They are both joint controllers of the information contained in the single order system

Buy Now
Exam Code: PDP9
Exam Name: BCS Practitioner Certificate in Data Protection
Last Update: Apr 30, 2026
Questions: 40

PDF + Testing Engine

$63.52  $181.49

Testing Engine

$50.57  $144.49
buy now PDP9 testing engine

PDF (Q&A)

$43.57  $124.49
buy now PDP9 pdf