A processor is instructed to report on customers who bought a product both last month and at least once in the three months before that. Unfortunately, the processor makes a mistake and uses personal data collected by another controller for a different purpose.
The mistake is found before the report is created, and nobody has access to personal date he or she should not have had access to.
How should the processor act on this situation and what should the controller do, if anything?
A security breach has occurred in an information system that also holds personal data. According to the GDPR, what is the very first thing the controller must do?
An Independent Supervisory Authority has several responsibilities. Which of the following is one of these?
The illegal collection, storage, modification, disclosure or dissemination of personal data is an offense under European law.
What kind of offense is this?
Organizations are obliged to keep a number of records to demonstrate compliance with the GDPR. Which record is not obligatory according to the GDPR?
A company’s director’s notebook is accidentally wet, which permanently damages the equipment so that it cannot recover its data.
The lost data concerned the financial reports of the company. What happened in this case according to GDPR?
Your credit card has been cloned. A card contains various personal information.
What category of data breach is this incident?
A company wishes to use personal data of their customers. They wish to start sending all female customers a customized newsletter. What right do all data subjects have in this scenario?
A shopkeeper wants to register how many visitors enter his shop every day. A system detects the MAC- address of each visitor’s smartphone. It is impossible for the shopkeeper to identify the owner of the phone from this signal, but telephone providers can link the MAC-address to the owner of the phone. According to the GDPR, is the shopkeeper allowed to use this method?
A secretary at a pediatric cardiology clinic instead of sending the doctor the list of patients scheduled for the day, sends it to all those responsible registered for the children with scheduled appointments.
According to the GDPR, does the Supervisory Authority need to be notified? And those responsible for the data holders?
The GDPR states that records of processing activities must be kept by the controller. To whom must the controller make these records available, if requested?
Which of the alternatives describes one of the Supervisory Authority’s responsibilities?
On July 12, 2016 the European Commission implemented a ruling regarding the transfer of personal data between the EEA and the US. The ruling is based on the data protection measures described in the EU-US Privacy Shield. What kind of a ruling is this?
Some data processing falls outside of the material scope of the GDPR. What type of processing is not subject to the GDPR?
In what way are online activities of people most effectively used by modern marketers?
According to the GDPR, for which situations should a Data Protection Impact Assessment (DPIA) be conducted?
Personal data as defined in the GDPR can be divided into several types. One of these types is described: Data that directly or indirectly reveal someone’s racial or ethnic background, political, philosophical, religious views, union affiliation and data related to health or sex life and sexual orientation. What type of personal data is this?
Subcontracting treatment is regulated by contract or other regulatory act under Union or Member State law, which links the processor to the controller.
What this contract or other regulatory act stipulates?
According to the GDPR, when is a data protection impact assessment (DPIA) obligatory?
According to the GDPR, what is the main reason to consider data protection in the initial design phase?
When personal data are processed, who is ultimately responsible for demonstrating compliance with the GDPR?
The controller responsible for the UK Child Sexual Abuse Investigation body reported a data breach to the
supervisory authority in the UK on 28 February 2019.
People who had registered their interest in participating in forums and debates for victims of child sexual abuse received an email that contained the email addresses of everyone else who had also registered.
Which category does this data breach fit into?
The Traffic Department of a city wants to know how many cars travel daily in order to plan the number of spaces needed to implement a rotating parking system.
To do this, cameras were installed at strategic points. Through image recognition software it is possible to capture the license plate and know how many cars traveled in the city. A monthly report is issued with the average number of cars present each day.
Signs and posters were spread around the city informing drivers and citizens what is the purpose of processing and that the data will be stored for up to five years, for future comparison.
What basic principle of legitimate processing of personal data is being violated in this case?
Under what EU legislation is data transfer between the EEA and the U.S.A. allowed?
A controller wants to switch processors. What is necessary to review before making this change, so that it remains GDPR compliant?
What is considered a personal data processing for the General Data Protection Regulation (GDPR)?
A good practice is to lock the computer automatically or manually when you are away from the workstation.
The company’s DPO realizes that this procedure is not being followed by employees. This occurrence should be classified in which category?
According to the General Data Protection Regulation (GDPR) which covers the concept “Compulsory Corporate Rules”?
A company located in France wishes to enter into a compulsory contract with a processor located in Portugal. This contract aims to process sensitive French personal data. The Portuguese Supervisory Authority is informed about this contract and the type of processing.
How should Portuguese Supervisory Authority proceed, in accordance with the General Data Protection Regulation (GDPR)?
The General Data Protection Regulation (GDPR) came into effect on May 25, 2018, what is the legal status of this regulation?