Font size
WorksheetsGDPR
Total questions: 91
Worksheet time: 57mins
Which of the following data protection milestones is a treaty among member states of the Council of Europe?
Directive Charter of Fundamental Rights
Convention 108’
e-Privacy Directive’
GDPR
Which of the following data protection milestones applies to public electronics communications services and networks?
Charter of Fundamental Rights
‘Convention 108’
‘e-Privacy Directive’
GDPR
4. Which European institution is composed of 47 member states?
The Council of Europe
The European Union
EUROPEAN economic Area
Which European institution is composed of 27 member states?
The Council of Europe
The European Union
The European Economic Area
Which European institution is composed of 28 member states?
The Council of Europe
The European Economic Area
The European Union
EFTA
In charge of Legislative Development, Supervisory of other institutions, Development of budget
European Council
European Parlament
European Comission
Court of Justice
Sets the political Direction of the EU ( political Agenda
European Parlament
Council of the EU
European Council
European Comission
In charge of the legislative decision making, They also examine proposal of the Comission
European Parlament
Council of the EU
European Council
Court of Justice
Implements the EU decisions and policies, Proposes legislation, are active Data Protectors,
European Parlament
Court of Justice
European Comission
Council of the EU
Based in Luxembourg, is the judicial Body of the EU, sets decisions and enforcement, and makes decisions on issues of the EU LAW
European Comission
European Parlament
Court of Justice
Council of the EU
What is the function of the 4 step Test
Determine if Data is ANON
Determine if data qualifies as personal Data
Extra Step
Determine if Data is Special
CRITERIA USED TO IDENTIFY PERSONAL DATA
any information
relating to
an identified or identifiable
natural person
Select the types of personal data elements that belong to special categories under the GDPR
Genetic Data
Data concerning health
Revealing political opinions
IP
personal data either belongs to special categories or does not. There is no grey area true or false?
(a)
Pseudonymous data is protected by the GDPR
true or false?
(a)
Anonymising personal data is always possible true or false?
(a)
True or false: A data controller may be a natural person or a legal entity, while a data processor must be a legal entity.
(a)
True or false: A contract protects a processor from being held to the same legal obligations as the controller.
(a)
True or false: A processor may decide where and how to process personal data.
(a)
True or false: When personal data is being processed, there always is a controller.
(a)
What is data processing?
Any action that adapts or alters data
Any operation performed upon data
Any action involved in collecting personal data
Any action involved in securing and protecting data
What are the criteria used to determine the territorial scope of the GDPR?
Processing of personal data when a controller or processor is established in the EU
Processing of personal data of EU subjects relating to offering goods or services or monitoring behaviour
Processing of personal data by a controller not established in the EU but in a place where member state law applies
Which of the following fall under the material scope of the GDPR? Select all that apply.
Processing personal data without human intervention
Processing personal data that forms part of a filing system
Processing anonymous data
. True or false: Exclusions to the material scope of the GDPR should be interpreted broadly.
(a)
True or false: At least three of the legitimate processing criteria within the GDPR must be met for personal data to be processed legally.
(a)
Read the following scenario and then select all the GDPR data processing principles that have been violated: An access control system used by an organisation's maintenance team for building security is later used by a manager in a different department to determine if employees are arriving late for work. The employees are not informed of this new processing action, and the manager does not create consistent records of the processing activities.
Data quality and accuracy
Accountability
Integrity and confidentiality
purpose limitation
Which legitimate processing criteria is commonly used when a customer purchases a good or service?
Contract
consent
Vital Interest
Which exception to the prohibition on processing special categories of data must be explicit?
Consent
Vital interest
Publicity available data
Select all that are potential solutions to lengthy privacy notices.
Standardised icons
'Just-in-time' notices
Layered privacy notices
Terms of agreement
True or false: A controller may charge an administrative fee to data subjects if they request that the information provision be in an oral format.
True
False
Privacy notices should use visualisation where appropriate.
True
false
Information provided to children about the processing of their personal data should be written in clear and plain language that is understandable.
True
false
The transparency principle states that detail is more important than conciseness in a privacy notice.
True
False
. What information must be provided to data subjects when their personal data will be stored on a database hosted in the United States?
Purpose
Intention to transfer data internationally
Controller's legitimate interest
Use of automated decision-making
What information must be provided to data subjects when the controller's necessity is being used as the legal basis for processing?
Source of the data
Controller's legitimate interest
Legal basis for transferring data internationally
Recipients of the data
What information must be provided to data subjects when the personal data that will be processed was collected indirectly?
Source of the data
Storage period
Controller's legitimate interest
Statutory or contractual requirement
What information must be provided to data subjects when their personal data will be shared with an outside organisation to provide them with a promised service?
Intention to transfer data internationally
Use of automated decision-making
Source of the data
Recipients of the data
What information must be provided to data subjects in all circumstances
Purpose of processing
Data subjects' rights
Data subjects rights
Identity of the controller
Controllets legitimate interest
Where would a full version of the privacy notice be located in a layered notice?
Top layer
Second layer
Third layer
True or false: Information provision should happen within a reasonable period of time.
True
False
True or false: Information provision is required, even if it necessitates disproportionate effort
True
False
True or false: Both controllers and processors have accountability obligations under the GDPR.
True
False
True or false: Data protection by default begins prior to processing and incorporates data protection considerations into the planning phase.
True
False
· What are the main values of a data protection impact assessment (DPIA)? Select all that apply.
Incorporating data protection considerations into organisational planning
Determining the purpose of processing personal data
Demonstrating compliance to supervisory authorities
· True or false: The GDPR requires controllers to always contact the supervisory authority following a DPIA and before processing of personal data.
True
False
· True or false: The GDPR requires a data protection policy to be used 'where proportionate in relation to processing activities'.
True
False
Which of the following must be included in controllers' personal data processing records but not in processors' records?
Purposes of processing
International data transfers being made and the measures put in place to ensure they are lawful
A general description of technical and organisational security measures that have been implemented
· The data protection officer must be an expert in data protection law and practices.
True
False
· Which of the following are circumstances that require an organisation to appoint a DPO? Select all that apply.
The controller is a public authority.
The core activities of the controller or processor include regular and systematic monitoring of data subjects on a large scale.
The core activities of the controller or processor consist of large-scale processing of special categories of data.
options for cross-border data transfers in the order that they should be considered.
Derogations
Adequacy decisions
Inadequate decisions
Appropriate safeguards
· Which of the following options for cross-border data transfers is a determination by the European Commission that a third country has achieved an EU-level of personal data protection?
Adequacy decision
Safeguard
Derogations
Countries that the European Comission has deemed adequate for cross border data transfers
Nez Zeland
Argentina
Israel
Mexico
Canada
Which of the following are EU-U.S. Privacy Shield requirements?
Publisie commitment
Self certification
Commit to the US Department of Commerce to adhere to PS principles
Imoplement the Principles
Privacy Shield Principles
Notice
Choice
Security
Acces
Recourse, enforcement and liability
Which of the following are appropriate safeguards for cross-border data transfers? Select all that apply.
Binding corporate rules
Standard contractual clauses
Public interest
Approved codes of conduct or certification Mechanisms
Legal bases for processing employees personal dara
Fulfilment of employment contract
Legal Obligation
Legitimate Interest of the Employer
Consent
Tasks and Responsibilities of DPO
Ensure Compliance
Manage Risk
Charge
Exercise professional secressy
Be a point of contact to supervisory authority
Controller and Processor requirement towards a DPO
Not fire him for perform his legal task
Provide all acces to personal data and processing operations
Facilitate communication
Ensure there is no conflict of interest ( his position requires determing purposes and means or being in certain positions
Risk in a DPIA should be considered from the point of view of:
Controller
Processor
Data Subject
Supervisory authority
Main Values of a DPIA
Help to demostrate compliance
Charge more money
Help incorporate Data Protection consideration
What may increase the likehood that a DPIA should be conducted.
Use of emerging technologioes
Use of Processors
Using Sensitive Data
Processing that will require DPIA
Conduct a systematic and extensive evaluation of Natural persons
Profiling
Process a Larger Scale of Special Categories
Process personal data relating to criminal convictions and offences
Systematic Monitoring in Larger Scale
Best practices for Data Protection Policies
Use concise and understandable language
Translate them
Use metrics to show results
Ensure the tasks are realistic, relevant and timely
how is determined a LARGER SCALE of data subjects
Volume
Range
Number of Data Subjects
Duration
Geographical extent of the processing
Which appropriate safeguards allow large multinational companies to adopt a policy suite with rules for handling personal data?
Binding corporate rules
Standard Contractual Clauses
Derogation
Public Interest
Adhoc contractual clauses
True or false: Criteria for derogations are strict and should be interpreted narrowly
True
False
DEROGATIONS
Explicit Consent
Necessary contract
Public Interest-
and
Vital Interest
Regiser of public informarion ( giving DS right to object)
Legitimate interest of controller. (NON REPETITIVE and a certain #)
Who does the GDPR task with promoting, monitoring and enforcing the GDPR?
Supervisory authorities
The European Data Protection Supervisor
How many active participants will the European Data Protection Board have?
1
5
7
31
Which of the following mechanisms facilitates the provision of relevant information between supervisory authorities?
Cooperation FOR REACH CONSENSUS
Mutual assistance
Consistency mechanism FOR ADOP MEASURES AND ENSURE A GDPR CONSISTENT APLICATION
Urgency procedure PROVISIONAL MEAURUES INMEDIATE
Which of the following mechanisms facilitates a specific collaborative process between supervisory authorities, the Commission and the European Data Protection Board for adopting certain measures and ensuring consistent GDPR application?
Cooperation
Consistency mechanism
Dispute resolution
Joint operations
Cross Border Definition Elements
Processing of Personal Data
Activities of Establisments of
More than 1 MS of a Controller or Processor In the EU
The processor or controller is stablished in more than 1 member State
If the processing is in fact cross-border processing, how does the controller identify the lead supervisory authority?
If the organisation has a single establishment in the EU, then the lead supervisory authority will simply be that of the place of establishment.
If the organisation has more than one establishment in the EU, then the lead supervisory authority will be that of the place of central administration.That is, unless
decisions about purposes, means and implementation of processing take place at a different location. If this is the case, then the SA of that location where the processing decisions take place will be the lead. This makes it possible for a company to have several lead SAs-if it conducts several cross-border activities whose related decisions take place in more than one location.
mechanisms to support cooperation and consistency between supervisory authorities.
cooperation
mutual assistance
Joint Operation
Consistency mechanism
Dispute resolution
Roles of the European Data Protection Board
Monitor for the correct application of the GDPR,
ersee the consistency mechanism for ensuring a consistent approach to data protection by the various supervisory authorities.
Issue guidance and advice to the Commission for personal data protection on a pan- European basis.
And preside over the dispute-resolution process.
· Which types of laws should be considered when processing employees' personal data? Select all that apply.
Local employment law
EU data protection law
Member state data protection law
What must be provided to employees when processing their personal data?
Opt-out
Notice that their personal data will be processed
Opt-in
The supervisory authority's contact information
True or false: Some employers may be required to consult with works councils and/or trade unions to process employees' personal data.
true
false
True or false: BYOD policies are designed to protect employees' personal data only.
false
true
Alternatives to employee monitoring should always be considered first.
true
false
What U.S. act requires companies to have a system in place to receive anonymous complaints about potential wrongdoing?
Barnes-Laramey Act (BLAME)
Washington's Whistle-blowing Act (WOW
Young-Underthorn Act (YOU)
Sarbanes-Oxley Act (SOX)
Which of the following statements is true of private-sector entities that conduct surveillance? Select all that apply.
They include bodies such as national security agencies and law enforcement authorities.
The surveillance they conduct must comply with national laws.
The surveillance they conduct must be based on legitimate purposes.
The e-Privacy Directive governs the processing of which types of data? Select all that apply.
Location data
Content data
Traffic data
True or false: Thee-Privacy Directive governs the processing of data through both private and public carriers and communications networks.
True
False
· Which of the following is not a data protection consideration associated with collecting personal data via CCTV?
Prior checking
Duration of the video
Lawfulness
Proportionality Individuals' rights
Information provision
Under the GDPR, individuals have the absolute right to object to any form of direct marketing at any time.
TRUE
FALSE
Which of the following statements is true regarding direct marketing channels?
For postal marketing, opt-in is required.
For telemarketing, opt-in is required.
For business-to-consumer emailing and text-messaging, opt-in is required.
True or false: Under the GDPR, web cookies qualify as personal data but IP addresses do not.
True
False
· When designing ways to actively collect personal data through a website, considerations may include:
Collection limitation.
Text Boxes
Access to the data protection notice.
Security obligation
When may a cloud services supplier be considered a controller?
When it determines substantial and essential elements of the means of processing; for example, data retention periods
When it is GDPR compliant.
When it processes data for its own purposes
When it determines aspects of the processing outside the controller's instructions
Even if the cloud provider is not directly subject to the GDPR, the cloud provider's customer in any case is not subject to it,
True
False
