Winter Sale Special 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: ex2p65

Exact2Pass Menu

Question # 4

In the GDPR, some types of personal data are regarded as special category personal data. Which personal data are considered special category personal data?


An address list of members of a political party


A genealogical register of someone’s ancestors


A list of payments made using a credit card

Full Access
Question # 5

According to the GDPR, what is a mandatory topic in a DPIA report?


Systematic description of the fiduciary duties to ensure compliance to all relevant laws and regulations


An assessment of the necessity and proportionality of the processing operations in relation to the purposes


The documentation of the risks to the rights and freedoms of the data protection officer


The measures envisaged to address the privacy compliance frameworks risks

Full Access
Question # 6

What is the main objective of the “Lifecycle Protection” principle?


All appropriate measures shall be taken to ensure that inaccurate data, taking into account the purposes for which they are processed, are erased or rectified without a delay.


The processing of data must take place in a manner that ensures its security, including protection against unauthorized or unlawful processing and accidental loss, destruction or damage.


Security measures should be in place from the moment data are collected until they are deleted.


Data must be collected for specified, explicit and legitimate purposes and may not be further processed in a manner incompatible with those purposes.

Full Access
Question # 7

We know that when a personal data breach occurs, the data controller (Controller) must notify the Supervisory Authority within 72 hours, without justified delay. However, should the Controller do if it is unable to communicate within this time?


Send the notification with the date of the violation changed, to remain within 72 hours.


After 72 hours there is no longer any need to send notification of personal data breach.


Do not notify and seek ways to hide the violation so that the Supervisory Authority or the titleholders are made aware


Send the notification, even after 72 hours, accompanied by the reasons for the delay

Full Access
Question # 8

Under what EU legislation is data transfer between the EEA and the U.S.A. allowed?


An adequacy decision based on the Privacy Shield program


An adequacy decision by reason of US domestic legislation


The Transatlantic Trade an Investment Partnership (TTIP)


The U.S.A.’s commitment to join the European Economic Area

Full Access
Question # 9

A company’s director’s notebook is accidentally wet, which permanently damages the equipment so that it cannot recover its data.

The lost data concerned the financial reports of the company. What happened in this case according to GDPR?


A vulnerability


A threat


A security incident


A data violation

Full Access
Question # 10

What is called the adequacy decision that allows data transfer between the United States and the European Economic Area (EEA)?


Regulation for transfer of personal data between EEA and USA/


Privacy Shield


General Data Protection Law (GDPL)


General Data Protection Regulation (GDPR)

Full Access
Question # 11

A good practice is to lock the computer automatically or manually when you are away from the workstation.

The company’s DPO realizes that this procedure is not being followed by employees. This occurrence should be classified in which category?


Classified as a security vulnerability


Classified as a security incident


There is no specific category.


Classified as a data breach

Full Access
Question # 12

A secretary at a pediatric cardiology clinic instead of sending the doctor the list of patients scheduled for the day, sends it to all those responsible registered for the children with scheduled appointments.

According to the GDPR, does the Supervisory Authority need to be notified? And those responsible for the data holders?


The Supervisory Authority must be notified, but there is no need to notify those responsible for the data subjects, as whoever had access to the data is also someone in the same situation.


The Supervisory Authority must be notified and also those responsible for the holders who had their data exposed.


There is no need to notify the Supervisory Authority, however those responsible for the holders who had

their data exposed must be notified.


There is no need to notify the Supervisory Authority or those responsible for the data subjects, as whoever had access to the data is also someone in the same situation.

Full Access
Question # 13

What does the principle of ‘data minimization’ mean?


Personal data shall be accurate and where necessary kept up to date.


Personal data shall be adequate and limited to what is necessary for the purposes of the processing.


Personal data shall be processed in a manner that ensures appropriate security of the personal data.


Personal data shall be processed lawfully, fairly and in a transparent manner in relation to the data subject.

Full Access
Question # 14

According to the GDPR, when is a data protection impact assessment (DPIA) obligatory?


When a project includes technologies or processes that use personal data


When processing is likely to result in a high risk to the rights of data subjects


When similar processing operations with comparable risks are repeated

Full Access
Question # 15

To plan the amount of parking space needed, a local government monitors and saves the license plate number of every car that enters and leaves the city center. They have obtained permission to collect data on the number of cars present in the city center. By comparing the license plate time of entry and exit the number of cars present every moment of each day is calculated. Each month a report is created detailing the average number of cars in the city center at specific moments for every day of the week. At every entrance to the city center, a billboard clearly states what data is collected by whom, the purpose of the processing and the fact that the license plate numbers are saved securely for up to two years, because the measurements will be repeated next year. Which of the basic principles for legitimate processing of personal data is violated in this scenario?


Personal data are processed in a manner that ensures appropriate security of the personal data.


Personal data are processed in a transparent manner in relation to the data subject


Personal data are kept in a form permitting identification of data subjects for no longer than is necessary.


Personal data are collected for specified, explicit and legitimate purposes and not further processed.

Full Access
Question # 16

Personal data as defined in the GDPR can be divided into several types. One of these types is described: Data that directly or indirectly reveal someone’s racial or ethnic background, political, philosophical, religious views, union affiliation and data related to health or sex life and sexual orientation. What type of personal data is this?


Direct personal data


Indirect personal data


Pseudonymized data


Special category personal data

Full Access
Question # 17

Which of the alternatives describes one of the Supervisory Authority’s responsibilities?


Supervise the processing of data of holders residing in a country belonging to the European Economic Area (EEA).


Consider the nature of the treatment, and as far as possible, assist the controller in order to enable the controller to fulfill his obligation.


Provide the controller with all necessary information to demonstrate compliance with obligations.


Apply technical and organizational measures to ensure that only personal data that are necessary for each specific purpose of processing are processed.

Full Access
Question # 18

The word privacy is never mentioned in the General Data Protection Regulation (GDPR) text.

Despite this, what would be the best definition of the privacy according to the Regulation?


The right not to have your life monitored by technologies.


Have freedom of expression.


The right to respect for private and family life, for home and communications.


The right to have your personal data protected.

Full Access
Question # 19

A controller discovers that a data subject, who had given consent for the processing of his data, has passed away. What this implies for data processing according to the General Data Protection Regulation (GDPR)?


With the death of the data owner, the controller can continue processing the data, as they are no longer under the GDPR.


The data can only be processed by the controller respecting the consent provided by the holder.


The controller must delete the data of the holder, since with the death of the holder the consent is automatically revoked.


The controller can process the data of a deceased person as long as it anonymizes the data.

Full Access
Question # 20

How is Data Lifecycle Management (DLM) related to data protection?


The DLM makes it possible to create a profile of the data subject.


DLM manages the data flow throughout its life cycle.


DLM makes it possible to know the risks and plans how to mitigate them.

Full Access
Question # 21

What does the GDPR concept of ‘binding corporate rules’ (BCR) imply?


A commission decision on the safety of data transfer to a third country


A set of rules used by a group of enterprises concerning personal data protection in international transfers


Measures to compensate for the lack of data protection in a third country


Rules covering data transfers between third countries

Full Access
Question # 22

Which of the following options is provided for in the GDPR and can be made by Member States?


Approve national provisions for implementation of GDPR.


Forcing the controller to notify the data subject of a breach.


Audit controller and processor safety processes.


Penalize controllers and processors.

Full Access