GDPR Quiz

GDPR Quiz

Assessment

Quiz

Other

KG - Professional Development

Hard

Used 6+ times

FREE Resource

Student preview

quiz-placeholder

5 questions

Show all answers

1.

MULTIPLE SELECT QUESTION

30 sec • 1 pt

General Data Protection Regulation (GDPR) seeks to protect personal data by giving individuals more rights over how their personal data is handled.


Which of the flowing could be classed as personal data under GDPR?

A Customers National Insurance Number.

A HMRC employee's ethnicity data.

A customer case file.

A customer email address.

2.

MULTIPLE SELECT QUESTION

30 sec • 1 pt

The GDPR expands the rights of all individuals in relation to their personal data. Which of these are 'Individual Rights' under GDPR?

The right to request corrections to their personal data (or 'rectification').

The right to access their personal data (Often exercised through a 'Subject Access Request')

Rights relating to automated decisions and automated profiling.

The right to be remembered.

3.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

What should you say when a customer states that HMRC needs their consent to legally handle their persona data?

Ask the customer's consent to continue processing.

Tell the customer that HMRC can process personal data when it needs to do son while carrying out its official functions as a government department, and in those circumstances does not need consent.

Ask the customer to complete a Subject Access Request (SAR).

Tell the customer that HMRC can process, store and retain any data for an unlimited period of time because it is a tax authority.

4.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

Subject Access Requests are a method by which customers can request access to the personal information organisations hold about them. The deadline for responding to these requests under GDPR is one Month. You have received a request from a customer for their personal information


What must you do now?

Respond to the customer directly and send them their persona data.

Deal with the request straightaway in line with your area's SAR's process.

Accept the deadline is in a months time, so take your time to prepare the data in the most appropriate format for the customer.

Collate all of the customers personal data and send this to your Data Protection contact.

5.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

Data breaches' under GDPR include data loss and unauthorised access, alteration or disclosure. Under GDPR we must report breaches to the Information Commissioners office within 72 Hours. If you think that there has been an incident that may be a data breach, what should you do?

Report it within one month to the Data Protection contact in your department.

Report it to the customer directly.

Immediately raise the incident via the Incident reporting Tool and inform your manager.

Report it to your Security and Information Business Partner (SIBP) team when you next see them.