Spring Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: pass65

PDPF Privacy and Data Protection Foundation Questions and Answers

Questions 4

A processor is instructed to report on customers who bought a product both last month and at least once in the three months before that. Unfortunately, the processor makes a mistake and uses personal data collected by another controller for a different purpose.

The mistake is found before the report is created, and nobody has access to personal date he or she should not have had access to.

How should the processor act on this situation and what should the controller do, if anything?

Options:

A.

The processor must notify the controller and the controller must notify the Data Protection Authority of a data breach.

B.

The processor must notify the controller of a data breach. The controller must assess the possible risk to the data subjects.

C.

The processor must notify the Data Protection Authority of a data breach. The controller must execute a PIA to assess the risk to data subjects.

D.

The processor must restart processing using the right data. There is no need for the controller to act.

Buy Now
Questions 5

A security breach has occurred in an information system that also holds personal data. According to the GDPR, what is the very first thing the controller must do?

Options:

A.

Assess the risk of adverse effects to the data subjects using a data protection impact assessment (DPIA)

B.

Ascertain whether the breach may have resulted in loss or unlawful processing of personal data

C.

Report the breach immediately to all data subjects and the relevant supervisory authority

D.

Assess whether personal data of a sensitive nature has or may have been unlawfully processed

Buy Now
Questions 6

An Independent Supervisory Authority has several responsibilities. Which of the following is one of these?

Options:

A.

Supervise the application of the General Data Protection Regulation (GDPR).

B.

Assist in the elaboration and adaptation of the specific data protection laws of each country.

C.

Conduct a Data Protection Impact Assessment (DPIA).

D.

Assist in the planning of a Personal Data Protection Management System when requested by the Controller.

Buy Now
Questions 7

What is the main purpose of the General Data Protection Regulation (GDPR)?

Options:

A.

Protecting the data of everyone in Europe.

B.

Protect the data of everyone in the world.

C.

Protect data of data subjects located in the European Economic Area (EEA), regardless of the country of processing.

D.

Protect confidential business data.

Buy Now
Questions 8

The illegal collection, storage, modification, disclosure or dissemination of personal data is an offense under European law.

What kind of offense is this?

Options:

A.

An offense related to content

B.

An offense to intellectual property

C.

An economic offense

D.

An offense to privacy

Buy Now
Questions 9

Organizations are obliged to keep a number of records to demonstrate compliance with the GDPR. Which record is not obligatory according to the GDPR?

Options:

A.

A record of notifications sent to the supervisory authority regarding processing of personal data

B.

A record of all intended processing together with the processing purpose(s) and legal justifications

C.

A record of processors including personal data provided and the period this data can be retained

D.

A record of data breaches with all relevant characteristics, including notifications

Buy Now
Questions 10

What is the definition of Controller according to GDPR?

Options:

A.

An independent public authority created by a Member State

B.

Individual or legal entity that, individually or in conjunction with others, determines the purposes and means of processing personal data.

C.

Individual or legal entity that is not authorized to process personal data.

D.

Individual or legal entity that processes personal data on behalf of the person responsible for processing personal data.

Buy Now
Questions 11

Which of the options below best represents data protection by design?

Options:

A.

It aims to incorporate security measures to protect data from the moment it is collected, throughout the processing and until its destruction at the end of the process

B.

It aims to ensure that personal data is automatically part of a protection process.

C.

It aims to create privacy impact analysis procedures (DPIA), notifications of breaches of privacy and fulfil requests from data subjects.

Buy Now
Questions 12

A company’s director’s notebook is accidentally wet, which permanently damages the equipment so that it cannot recover its data.

The lost data concerned the financial reports of the company. What happened in this case according to GDPR?

Options:

A.

A vulnerability

B.

A threat

C.

A security incident

D.

A data violation

Buy Now
Questions 13

Your credit card has been cloned. A card contains various personal information.

What category of data breach is this incident?

Options:

A.

Material

B.

Digital

C.

Verbal

Buy Now
Questions 14

A company wishes to use personal data of their customers. They wish to start sending all female customers a customized newsletter. What right do all data subjects have in this scenario?

Options:

A.

The right to rectification

B.

The right to compensation

C.

The right to object to profiling

Buy Now
Questions 15

A shopkeeper wants to register how many visitors enter his shop every day. A system detects the MAC- address of each visitor’s smartphone. It is impossible for the shopkeeper to identify the owner of the phone from this signal, but telephone providers can link the MAC-address to the owner of the phone. According to the GDPR, is the shopkeeper allowed to use this method?

Options:

A.

Yes, because the shopkeeper cannot identify the owner of the telephone

B.

No, because the telephone providers are the owners of the MAC-addresses.

C.

No, because the telephone’s MAC-address must be regarded as personal data.

D.

Yes, because the visitor has automatically consented by connecting to the Wi-Fi

Buy Now
Questions 16

A secretary at a pediatric cardiology clinic instead of sending the doctor the list of patients scheduled for the day, sends it to all those responsible registered for the children with scheduled appointments.

According to the GDPR, does the Supervisory Authority need to be notified? And those responsible for the data holders?

Options:

A.

The Supervisory Authority must be notified, but there is no need to notify those responsible for the data subjects, as whoever had access to the data is also someone in the same situation.

B.

The Supervisory Authority must be notified and also those responsible for the holders who had their data exposed.

C.

There is no need to notify the Supervisory Authority, however those responsible for the holders who had

their data exposed must be notified.

D.

There is no need to notify the Supervisory Authority or those responsible for the data subjects, as whoever had access to the data is also someone in the same situation.

Buy Now
Questions 17

What is the purpose of Data Lifecycle Management (DLM)?

Options:

A.

Ensure data integrity and its periodic update

B.

Ensure data confidentiality and availability throughout its useful life.

C.

Ensure that the processing of personal data, throughout its useful life complies with the GDPR

D.

Ensure data confidentiality throughout its useful life, from collection to deletion.

Buy Now
Questions 18

The GDPR states that records of processing activities must be kept by the controller. To whom must the controller make these records available, if requested?

Options:

A.

The data processor

B.

The Data Protection Officer

C.

The European Commission

D.

The supervisory authority

Buy Now
Questions 19

Which of the alternatives describes one of the Supervisory Authority’s responsibilities?

Options:

A.

Supervise the processing of data of holders residing in a country belonging to the European Economic Area (EEA).

B.

Consider the nature of the treatment, and as far as possible, assist the controller in order to enable the controller to fulfill his obligation.

C.

Provide the controller with all necessary information to demonstrate compliance with obligations.

D.

Apply technical and organizational measures to ensure that only personal data that are necessary for each specific purpose of processing are processed.

Buy Now
Questions 20

Regarding the Portability Law for data subjects, which option is correct?

Options:

A.

The data subject has the right to object at any time, for reasons related to their particular situation, so that the data is not shared between controllers.

B.

The data subject has the right to ask the controller to rectify, erase or limit the processing of personal data with respect to the data subject if he has shared his data.

C.

The data owner has the right to transmit his data to another controller without the controller that already has the personal data provided being able to prevent it.

D.

The data subject has the right to obtain from the controller the limitation of processing so that the data is shared.

Buy Now
Questions 21

On July 12, 2016 the European Commission implemented a ruling regarding the transfer of personal data between the EEA and the US. The ruling is based on the data protection measures described in the EU-US Privacy Shield. What kind of a ruling is this?

Options:

A.

Derogation

B.

Legally binding contract

C.

Treaty superseding the GDPR

D.

Adequacy decision

Buy Now
Questions 22

Some data processing falls outside of the material scope of the GDPR. What type of processing is not subject to the GDPR?

Options:

A.

Creating a back-up of biometric data for data security purposes

B.

Collecting name and address information for a gymnastics club

C.

Editing personal photographs before printing them at home

Buy Now
Questions 23

In what way are online activities of people most effectively used by modern marketers?

Options:

A.

By analyzing the logs of the web server it can be seen which products are top sellers, allowing them to optimize their marketing campaigns for those products.

B.

By tagging users of social media, profiles of their online behavior can be created. These profiles are used to ask them to promote a product.

C.

By tagging visitors of web pages, profiles of their online behavior can be created. These profiles are sold and used in targeted advertisement campaigns.

Buy Now
Questions 24

According to the GDPR, for which situations should a Data Protection Impact Assessment (DPIA) be conducted?

Options:

A.

For all projects that include technologies or processes that require data protection

B.

For all sets of similar processing operations with comparable risks

C.

For any situation where technologies and processes will be subject to a risk assessment

D.

For technologies and processes that are likely to result in a high risk to the rights of data subjects

Buy Now
Questions 25

Personal data as defined in the GDPR can be divided into several types. One of these types is described: Data that directly or indirectly reveal someone’s racial or ethnic background, political, philosophical, religious views, union affiliation and data related to health or sex life and sexual orientation. What type of personal data is this?

Options:

A.

Direct personal data

B.

Indirect personal data

C.

Pseudonymized data

D.

Special category personal data

Buy Now
Questions 26

What is a responsibility of Supervisory Authorities in EEA countries?

Options:

A.

Research on security breaches of corporate information

B.

Supervision of all data processing operations controlled by a controller in an EEA country

C.

Supervision of all data processing operations where the data subjects are residents of an EEA country

Buy Now
Questions 27

Subcontracting treatment is regulated by contract or other regulatory act under Union or Member State law, which links the processor to the controller.

What this contract or other regulatory act stipulates?

Options:

A.

A process for testing, assessing and regularly evaluating the effectiveness of technical and organizational measures to ensure safe treatment.

B.

The processor assists the driver through technical and organizational measures to enable it to fulfill its obligation to respond to requests from data subjects.

C.

The description of categories of data subjects and categories of personal data

D.

The purpose of data processing

Buy Now
Questions 28

According to the GDPR, when is a data protection impact assessment (DPIA) obligatory?

Options:

A.

When a project includes technologies or processes that use personal data

B.

When processing is likely to result in a high risk to the rights of data subjects

C.

When similar processing operations with comparable risks are repeated

Buy Now
Questions 29

According to the GDPR, what is the main reason to consider data protection in the initial design phase?

Options:

A.

It ensures efficiency in project phases

B.

It ensures privacy by default

C.

It reduces the risk of fraud

D.

It reduces the risk of liability

Buy Now
Questions 30

When personal data are processed, who is ultimately responsible for demonstrating compliance with the GDPR?

Options:

A.

Data protection officer (DPO)

B.

Supervisory authority

C.

Processor

D.

Controller

Buy Now
Questions 31

The controller responsible for the UK Child Sexual Abuse Investigation body reported a data breach to the

supervisory authority in the UK on 28 February 2019.

People who had registered their interest in participating in forums and debates for victims of child sexual abuse received an email that contained the email addresses of everyone else who had also registered.

Which category does this data breach fit into?

Options:

A.

This data breach should only be reported to the Data Protection Authority.

B.

This data breach should only be reported to data subjects.

C.

It is not necessary to notify the Supervisory Authority, as this data breach presents minimal risks to the holders.

D.

This data breach must be reported to the Data Protection Authority and the data subjects.

Buy Now
Questions 32

When does the GDPR require data subjects consent to a cookie?

Options:

A.

Always, because a cookie is regarded as online identifier

B.

Never, as the EU Cookie Law does not require explicit consent

C.

Only if the cookie contains authentication information of the data subject

D.

Only if the cookie contains shopping basket items

Buy Now
Questions 33

The Traffic Department of a city wants to know how many cars travel daily in order to plan the number of spaces needed to implement a rotating parking system.

To do this, cameras were installed at strategic points. Through image recognition software it is possible to capture the license plate and know how many cars traveled in the city. A monthly report is issued with the average number of cars present each day.

Signs and posters were spread around the city informing drivers and citizens what is the purpose of processing and that the data will be stored for up to five years, for future comparison.

What basic principle of legitimate processing of personal data is being violated in this case?

Options:

A.

Personal data must be kept in a way that allows the identification of data subjects for a period not longer than necessary.

B.

Personal data must be processed transparently in relation to the data subject.

C.

Personal data must be processed in a way that guarantees the appropriate security of personal data.

D.

Personal data must be collected for specific, explicit and legitimate purposes and must not be further processed for incompatible purposes.

Buy Now
Questions 34

Under what EU legislation is data transfer between the EEA and the U.S.A. allowed?

Options:

A.

An adequacy decision based on the Privacy Shield program

B.

An adequacy decision by reason of US domestic legislation

C.

The Transatlantic Trade an Investment Partnership (TTIP)

D.

The U.S.A.’s commitment to join the European Economic Area

Buy Now
Questions 35

Which of these options is an example of a data breach?

Options:

A.

Transfer of personal data outside the EU

B.

Loss of personal data

C.

A security incident related to corporate data.

Buy Now
Questions 36

A controller wants to switch processors. What is necessary to review before making this change, so that it remains GDPR compliant?

Options:

A.

The matrix location of this new processor.

B.

Require the old processor to erase data.

C.

Require the old processor to port the data.

D.

Verify that the new processor has sufficient security guarantees.

Buy Now
Questions 37

Which cause is a data breach according to the GDPR?

Options:

A.

illegally obtained corporate data from a human resources management system

B.

Personal data is processed without a binding contract.

C.

Personal data is processed by anyone other than the controller, processor or, possibly, subprocessor

D.

The operation of a vulnerable server in the internal network of the processor

Buy Now
Questions 38

What is considered a personal data processing for the General Data Protection Regulation (GDPR)?

Options:

A.

Analysis of data regarding the cause of death in the last 10 years.

B.

Creating a backup with records of names, addresses, enrollment of students.

C.

Conducting analysis of personal data related to health issues, but which have previously been anonymized.

D.

Statistical publication with intention to vote, help anonymously.

Buy Now
Questions 39

A good practice is to lock the computer automatically or manually when you are away from the workstation.

The company’s DPO realizes that this procedure is not being followed by employees. This occurrence should be classified in which category?

Options:

A.

Classified as a security vulnerability

B.

Classified as a security incident

C.

There is no specific category.

D.

Classified as a data breach

Buy Now
Questions 40

According to the General Data Protection Regulation (GDPR) which covers the concept “Compulsory Corporate Rules”?

Options:

A.

Decision made by a corporation to transfer data to another country.

B.

Contractual clauses to transfer data to a country that does not have a data protection law.

C.

A set of rules used by a group of companies regarding the protection of personal data in international transfers

D.

Rules covering data transfers between several countries.

Buy Now
Questions 41

A company located in France wishes to enter into a compulsory contract with a processor located in Portugal. This contract aims to process sensitive French personal data. The Portuguese Supervisory Authority is informed about this contract and the type of processing.

How should Portuguese Supervisory Authority proceed, in accordance with the General Data Protection Regulation (GDPR)?

Options:

A.

Supervise the processing of personal data according to the guidelines of the Supervisory Authority of Portugal.

B.

Report the data processing to the French Supervisory Authority, which must take over the supervision.

C.

Verify that adequate compulsory contracts have been established and leave supervision to the French Supervisory Authority.

D.

Supervise the processing of personal data in accordance with the French Supervisory Authority legislation.

Buy Now
Questions 42

The General Data Protection Regulation (GDPR) came into effect on May 25, 2018, what is the legal status of this regulation?

Options:

A.

The GDPR is a functional law in all EU member states and Member States cannot rectify it.

B.

The GDPR is only a recommendation. Member States should create laws to suit

C.

Some articles in the GDPR provide guidance and allow Member States to draft more specific laws to suit.

Buy Now
Questions 43

How is Data Lifecycle Management (DLM) related to data protection?

Options:

A.

The DLM makes it possible to create a profile of the data subject.

B.

DLM manages the data flow throughout its life cycle.

C.

DLM makes it possible to know the risks and plans how to mitigate them.

Buy Now
Questions 44

According to the GDPR, what is a description of binding corporate rules (BCR)?

Options:

A.

A decision on the safety of transferring personal data to a non-EEA country

B.

A set of approved rules on personal data protection used by a group of enterprises

C.

A measure to compensate for the lack of personal data protection in a third country

D.

A set of agreements covering personal data transfers between non-EEA countries

Buy Now
Exam Code: PDPF
Exam Name: Privacy and Data Protection Foundation
Last Update: May 5, 2026
Questions: 149

PDF + Testing Engine

$63.52  $181.49

Testing Engine

$50.57  $144.49
buy now PDPF testing engine

PDF (Q&A)

$43.57  $124.49
buy now PDPF pdf