Labour Day Limited Time 60% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 2493360325

Good News !!! PDPF Privacy and Data Protection Foundation is now Stable and With Pass Result

PDPF Practice Exam Questions and Answers

Privacy and Data Protection Foundation

Last Update 1 day ago
Total Questions : 149

PDPF is stable now with all latest exam questions are added 1 day ago. Just download our Full package and start your journey with Exin Privacy and Data Protection Foundation certification. All these Exin PDPF practice exam questions are real and verified by our Experts in the related industry fields.

PDPF PDF

PDPF PDF (Printable)
$48
$119.99

PDPF Testing Engine

PDPF PDF (Printable)
$56
$139.99

PDPF PDF + Testing Engine

PDPF PDF (Printable)
$70.8
$176.99
Question # 1

When personal data are processed, who is ultimately responsible for demonstrating compliance with the GDPR?

Options:

A.  

Data protection officer (DPO)

B.  

Supervisory authority

C.  

Processor

D.  

Controller

Discussion 0
Question # 2

We know that when a personal data breach occurs, the data controller (Controller) must notify the Supervisory Authority within 72 hours, without justified delay. However, should the Controller do if it is unable to communicate within this time?

Options:

A.  

Send the notification with the date of the violation changed, to remain within 72 hours.

B.  

After 72 hours there is no longer any need to send notification of personal data breach.

C.  

Do not notify and seek ways to hide the violation so that the Supervisory Authority or the titleholders are made aware

D.  

Send the notification, even after 72 hours, accompanied by the reasons for the delay

Discussion 0
Question # 3

The GDPR describes the principle of data minimization. How can organizations comply with this principle?

Options:

A.  

By applying the concept of least privilege to the personal data collected, stored or otherwise processed.

B.  

By limiting access rights to staff who need the personal data for the intended processing operations

C.  

By limiting the personal data to what is adequate, relevant and necessary for the processing purposes

D.  

By limiting file sizes, through saving all personal data that is processed in the smallest possible format

Discussion 0
Question # 4

According to the GDPR, for which situations should a Data Protection Impact Assessment (DPIA) be conducted?

Options:

A.  

For all projects that include technologies or processes that require data protection

B.  

For all sets of similar processing operations with comparable risks

C.  

For any situation where technologies and processes will be subject to a risk assessment

D.  

For technologies and processes that are likely to result in a high risk to the rights of data subjects

Discussion 0
Question # 5

A person buys a product at a store located in the European Economic Area (EEA). At the time of purchase, you are asked to fill out a registration form and he informs his personal email.

As is usual in many stores, in the next few days this person will start receiving several marketing emails. He considers the frequency of these emails to be very high. Demanding his rights, he asks the store to delete all his personal data.

What the store must do according to the General Data Protection Regulation (GDPR)?

Options:

A.  

The owner does not have this right, since he bought a product in the store, he has the right to send emails with new promotions.

B.  

The store has 30 days from the date of receipt of the customer’s request to delete all data at no cost to the customer.

C.  

The store must delete customer data from its advertising list. Purchase data cannot be deleted, as financial data has to be kept longer.

Discussion 0
Question # 6

A written contract between a controller and a processor is called a data processing agreement. According to

the GDPR, what does not have to be covered in the written contract?

Options:

A.  

The contractor code of business ethics and conduct that is used.

B.  

Which data are covered by the data processing agreement

C.  

The information security and personal data breach procedures

D.  

The technical and organizational measures implemented

Discussion 0
Question # 7

Which cause is a data breach according to the GDPR?

Options:

A.  

illegally obtained corporate data from a human resources management system

B.  

Personal data is processed without a binding contract.

C.  

Personal data is processed by anyone other than the controller, processor or, possibly, subprocessor

D.  

The operation of a vulnerable server in the internal network of the processor

Discussion 0
Question # 8

What is called the adequacy decision that allows data transfer between the United States and the European Economic Area (EEA)?

Options:

A.  

Regulation for transfer of personal data between EEA and USA/

B.  

Privacy Shield

C.  

General Data Protection Law (GDPL)

D.  

General Data Protection Regulation (GDPR)

Discussion 0
Question # 9

Which organizations need to comply with the General Data Protection Regulation (GDPR)?

Options:

A.  

Only organizations that have employees in the European Union (EU).

B.  

Only organizations that have their headquarters in the European Union (EU).

C.  

All organizations anywhere in the world.

D.  

All organizations located in the European Union and also organizations outside the European Union that offer goods or services to data subjects in the EU.

Discussion 0
Question # 10

The word privacy is never mentioned in the General Data Protection Regulation (GDPR) text.

Despite this, what would be the best definition of the privacy according to the Regulation?

Options:

A.  

The right not to have your life monitored by technologies.

B.  

Have freedom of expression.

C.  

The right to respect for private and family life, for home and communications.

D.  

The right to have your personal data protected.

Discussion 0
Question # 11

To comply with the General Data Protection Regulation (GDPR) it is necessary to create a procedure for reporting data breaches to the Supervisory Authority.

As the controller is a public administration agency, which option is a requirement for this procedure?

Options:

A.  

It must contain a step to perform a Data Protection Impact Analysis (DPIA).

B.  

It must include an audit step.

C.  

It should include a step to consult the Data Protection Officer (DPO) in order to determine whether notification to the Supervisory Authority is necessary.

D.  

It must contain a step to notify the data subject.

Discussion 0
Question # 12

A gentleman has a loan denied by the bank’s system that he has been a customer for many years. He is disgusted, because the loan would make it possible to hold the wedding of his only granddaughter.

He contacts the bank and asks for explanations. He wants to know exactly why his loan was denied and based on what information.

What right is required by the data subject according to the GDPR?

Options:

A.  

Right to limitation of treatment

B.  

Right to rectification

C.  

Data subject’s right of access

D.  

Right to object and automated individual decision-making

Discussion 0
Question # 13

The GDPR contains several items. Which of these contains mandatory requirements?

Options:

A.  

Recitals

B.  

Articles

Discussion 0
Question # 14

A secretary at a pediatric cardiology clinic instead of sending the doctor the list of patients scheduled for the day, sends it to all those responsible registered for the children with scheduled appointments.

According to the GDPR, does the Supervisory Authority need to be notified? And those responsible for the data holders?

Options:

A.  

The Supervisory Authority must be notified, but there is no need to notify those responsible for the data subjects, as whoever had access to the data is also someone in the same situation.

B.  

The Supervisory Authority must be notified and also those responsible for the holders who had their data exposed.

C.  

There is no need to notify the Supervisory Authority, however those responsible for the holders who had

their data exposed must be notified.

D.  

There is no need to notify the Supervisory Authority or those responsible for the data subjects, as whoever had access to the data is also someone in the same situation.

Discussion 0
Question # 15

In its Article 9 the GDPR categorizes some types of personal data as “sensitive”.

Of these below which are considered sensitive?

Options:

A.  

Date of birth of a person.

B.  

A person’s home address.

C.  

Soccer team that a person supports.

D.  

Result of a medical examination.

Discussion 0
Question # 16

A shopkeeper wants to register how many visitors enter his shop every day. A system detects the MAC- address of each visitor’s smartphone. It is impossible for the shopkeeper to identify the owner of the phone from this signal, but telephone providers can link the MAC-address to the owner of the phone. According to the GDPR, is the shopkeeper allowed to use this method?

Options:

A.  

Yes, because the shopkeeper cannot identify the owner of the telephone

B.  

No, because the telephone providers are the owners of the MAC-addresses.

C.  

No, because the telephone’s MAC-address must be regarded as personal data.

D.  

Yes, because the visitor has automatically consented by connecting to the Wi-Fi

Discussion 0
Question # 17

Subcontracting treatment is regulated by contract or other regulatory act under Union or Member State law, which links the processor to the controller.

What this contract or other regulatory act stipulates?

Options:

A.  

A process for testing, assessing and regularly evaluating the effectiveness of technical and organizational measures to ensure safe treatment.

B.  

The processor assists the driver through technical and organizational measures to enable it to fulfill its obligation to respond to requests from data subjects.

C.  

The description of categories of data subjects and categories of personal data

D.  

The purpose of data processing

Discussion 0
Question # 18

The General Data Protection Regulation (GDPR) is based on the principles of proportionality and subsidiarity.

What is the meaning of “proportionality” in this context?

Options:

A.  

Personal data can be processed according to the use of requirements.

B.  

Personal data cannot be reused without explicit and informed consent.

C.  

Personal data can only be processed if there are no other means to achieve the purposes.

D.  

Personal data must be adequate, relevant and not excessive in relation to the purposes.

Discussion 0
Question # 19

A personal data breach has occurred, and the controller is writing a draft notification for the supervisory authority. The following information is already in the notification:

-The nature of the personal data breach and its possible consequences.

-Information regarding the parties that can provide additional information about the data breach.

What other information must the controller provide?

Options:

A.  

Information of local and national authorities that were informed about the data breach.

B.  

Name and contact details of the data subjects whose data may have been breached

C.  

Suggested measures to mitigate the adverse consequences of the data breach.

D.  

The information needed to access the personal data that have been breached.

Discussion 0
Question # 20

What is the term used in the General Data Protection Regulation (GDPR) for the disclosure of, or unauthorized access to, personal data?

Options:

A.  

Security incident

B.  

Incident

C.  

Breach of confidentiality

D.  

Data breach

Discussion 0
Question # 21

The General Data Protection Regulation (GDPR) in its Article 30 legislates on the Records of treatment activities.

If requested, the controller must provide these records:

Options:

A.  

To the data processor

B.  

To the Data Protection Officer (DPO)

C.  

The supervisory authority

D.  

To the European Commission

Discussion 0
Question # 22

Personal data shall be adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed. Which data processing principle is described here?

Options:

A.  

Purpose limitation

B.  

Data minimization

C.  

Accuracy

D.  

Fairness and transparency

Discussion 0
Get PDPF dumps and pass your exam in 24 hours!

Free Exams Sample Questions