wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

GDPR

Total questions: 91

Worksheet time: 57mins

Name
Class
Date
1.

Which of the following data protection milestones is a treaty among member states of the Council of Europe?

a)

Directive Charter of Fundamental Rights

b)

Convention 108’

c)

e-Privacy Directive’

d)

GDPR

2.

Which of the following data protection milestones applies to public electronics communications services and networks?

a)

Charter of Fundamental Rights

b)

‘Convention 108’

c)

‘e-Privacy Directive’

d)

GDPR

3.

4. Which European institution is composed of 47 member states?

a)

The Council of Europe

b)

The European Union

c)

EUROPEAN economic Area

4.

Which European institution is composed of 27 member states?

a)

The Council of Europe

b)

The European Union

c)

The European Economic Area

5.

Which European institution is composed of 28 member states?

a)

The Council of Europe

b)

The European Economic Area

c)

The European Union

d)

EFTA

6.

In charge of Legislative Development, Supervisory of other institutions, Development of budget

a)

European Council

b)

European Parlament

c)

European Comission

d)

Court of Justice

7.

Sets the political Direction of the EU ( political Agenda

a)

European Parlament

b)

Council of the EU

c)

European Council

d)

European Comission

8.

In charge of the legislative decision making, They also examine proposal of the Comission

a)

European Parlament

b)

Council of the EU

c)

European Council

d)

Court of Justice

9.

Implements the EU decisions and policies, Proposes legislation, are active Data Protectors,

a)

European Parlament

b)

Court of Justice

c)

European Comission

d)

Council of the EU

10.

Based in Luxembourg, is the judicial Body of the EU, sets decisions and enforcement, and makes decisions on issues of the EU LAW

a)

European Comission

b)

European Parlament

c)

Court of Justice

d)

Council of the EU

11.

What is the function of the 4 step Test

a)

Determine if Data is ANON

b)

Determine if data qualifies as personal Data

c)

Extra Step

d)

Determine if Data is Special

12.

CRITERIA USED TO IDENTIFY PERSONAL DATA

a)

any information

b)

relating to

c)

an identified or identifiable

d)

natural person

13.

Select the types of personal data elements that belong to special categories under the GDPR

a)

Genetic Data

b)

Data concerning health

c)

Revealing political opinions

d)

IP

14.

personal data either belongs to special categories or does not. There is no grey area true or false?

(a)  

15.

Pseudonymous data is protected by the GDPR

true or false?

(a)  

16.

Anonymising personal data is always possible true or false?

(a)  

17.

True or false: A data controller may be a natural person or a legal entity, while a data processor must be a legal entity.

(a)  

18.

True or false: A contract protects a processor from being held to the same legal obligations as the controller.

(a)  

19.

 

True or false: A processor may decide where and how to process personal data.

(a)  

20.

 

True or false: When personal data is being processed, there always is a controller.

(a)  

21.

What is data processing?

a)

Any action that adapts or alters data

b)

Any operation performed upon data

c)

Any action involved in collecting personal data

d)

Any action involved in securing and protecting data

22.

What are the criteria used to determine the territorial scope of the GDPR?

a)

Processing of personal data when a controller or processor is established in the EU

b)

Processing of personal data of EU subjects relating to offering goods or services or monitoring behaviour

c)

Processing of personal data by a controller not established in the EU but in a place where member state law applies

23.

Which of the following fall under the material scope of the GDPR? Select all that apply.

 

a)

Processing personal data without human intervention

b)

Processing personal data that forms part of a filing system

 

c)

Processing anonymous data

24.

. True or false: Exclusions to the material scope of the GDPR should be interpreted broadly.

(a)  

25.

True or false: At least three of the legitimate processing criteria within the GDPR must be met for personal data to be processed legally.

(a)  

26.

 

 

Read the following scenario and then select all the GDPR data processing principles that have been violated: An access control system used by an organisation's maintenance team for building security is later used by a manager in a different department to determine if employees are arriving late for work. The employees are not informed of this new processing action, and the manager does not create consistent records of the processing activities.

 

a)

Data quality and accuracy

b)

Accountability

c)

Integrity and confidentiality

d)

purpose limitation

27.

Which legitimate processing criteria is commonly used when a customer purchases a good or service?

a)

Contract

b)

consent

c)

Vital Interest

28.

Which exception to the prohibition on processing special categories of data must be explicit?

a)

Consent

b)

Vital interest

c)

Publicity available data

29.

Select all that are potential solutions to lengthy privacy notices.

a)

Standardised icons

b)

'Just-in-time' notices

c)

 Layered privacy notices

d)

Terms of agreement

30.

True or false: A controller may charge an administrative fee to data subjects if they request that the information provision be in an oral format.

a)

True

b)

False

31.

 Privacy notices should use visualisation where appropriate.

a)

True

b)

false

32.

Information provided to children about the processing of their personal data should be written in clear and plain language that is understandable.

a)

True

b)

false

33.

The transparency principle states that detail is more important than conciseness in a privacy notice.

a)

True

b)

False

34.

 

. What information must be provided to data subjects when their personal data will be stored on a database hosted in the United States?

 

a)

Purpose

b)

Intention to transfer data internationally

c)

 Controller's legitimate interest

d)

Use of automated decision-making

35.

What information must be provided to data subjects when the controller's necessity is being used as the legal basis for processing?

a)

Source of the data

b)

Controller's legitimate interest

c)

Legal basis for transferring data internationally

d)

Recipients of the data

36.

What information must be provided to data subjects when the personal data that will be processed was collected indirectly?

a)

Source of the data

b)

Storage period

c)

Controller's legitimate interest

d)

Statutory or contractual requirement

37.

What information must be provided to data subjects when their personal data will be shared with an outside organisation to provide them with a promised service?

a)

Intention to transfer data internationally

b)

Use of automated decision-making

c)

Source of the data

d)

Recipients of the data

38.

What information must be provided to data subjects in all circumstances

 

a)

Purpose of processing

b)

Data subjects' rights

c)

Data subjects rights

d)

Identity of the controller

e)

Controllets legitimate interest

39.

Where would a full version of the privacy notice be located in a layered notice?

a)

Top layer

b)

Second layer

c)

Third layer

40.

True or false: Information provision should happen within a reasonable period of time.

a)

True

b)

False

41.

True or false: Information provision is required, even if it necessitates disproportionate effort

a)

True

b)

False

42.

True or false: Both controllers and processors have accountability obligations under the GDPR.

a)

True

b)

False

43.

True or false: Data protection by default begins prior to processing and incorporates data protection considerations into the planning phase.

a)

True

b)

False

44.

·       What are the main values of a data protection impact assessment (DPIA)? Select all that apply.

a)

Incorporating data protection considerations into organisational planning

b)

Determining the purpose of processing personal data

c)

Demonstrating compliance to supervisory authorities

45.

·      True or false: The GDPR requires controllers to always contact the supervisory authority following a DPIA and before processing of personal data.

a)

True

b)

False

46.

·       True or false: The GDPR requires a data protection policy to be used 'where proportionate in relation to processing activities'.

a)

True

b)

False

47.

Which of the following must be included in controllers' personal data processing records but not in processors' records?

a)

Purposes of processing

b)

International data transfers being made and the measures put in place to ensure they are lawful

c)

A general description of technical and organisational security measures that have been implemented

48.

·       The data protection officer must be an expert in data protection law and practices.

a)

True

b)

False

49.

 

·       Which of the following are circumstances that require an organisation to appoint a DPO? Select all that apply.

a)

 

The controller is a public authority.

b)

The core activities of the controller or processor include regular and systematic monitoring of data subjects on a large scale.

c)

 

The core activities of the controller or processor consist of large-scale processing of special categories of data.

50.

options for cross-border data transfers in the order that they should be considered.

a)

 Derogations

b)

Adequacy decisions

c)

Inadequate decisions

d)

Appropriate safeguards

51.

·       Which of the following options for cross-border data transfers is a determination by the European Commission that a third country has achieved an EU-level of personal data protection?

a)

Adequacy decision

b)

Safeguard

c)

Derogations

52.

Countries that the European Comission has deemed adequate for cross border data transfers

a)

Nez Zeland

b)

Argentina

c)

Israel

d)

Mexico

e)

Canada

53.

Which of the following are EU-U.S. Privacy Shield requirements?

 

 

a)

Publisie commitment

b)

Self certification

c)

Commit to the US Department of Commerce to adhere to PS principles

d)

Imoplement the Principles

54.

Privacy Shield Principles

a)

Notice

b)

Choice

c)

Security

d)

Acces

e)

Recourse, enforcement and liability

55.

Which of the following are appropriate safeguards for cross-border data transfers? Select all that apply.

a)

Binding corporate rules

b)

Standard contractual clauses

c)

Public interest

d)

Approved codes of conduct or certification Mechanisms

56.

Legal bases for processing employees personal dara

a)

Fulfilment of employment contract

b)

Legal Obligation

c)

Legitimate Interest of the Employer

d)

Consent

57.

Tasks and Responsibilities of DPO

a)

Ensure Compliance

b)

Manage Risk

c)

Charge

d)

Exercise professional secressy

e)

Be a point of contact to supervisory authority

58.

Controller and Processor requirement towards a DPO

a)

Not fire him for perform his legal task

b)

Provide all acces to personal data and processing operations

c)

Facilitate communication

d)

Ensure there is no conflict of interest ( his position requires determing purposes and means or being in certain positions

59.

Risk in a DPIA should be considered from the point of view of:

a)

Controller

b)

Processor

c)

Data Subject

d)

Supervisory authority

60.

Main Values of a DPIA

a)

Help to demostrate compliance

b)

Charge more money

c)

Help incorporate Data Protection consideration

61.

What may increase the likehood that a DPIA should be conducted.

a)

Use of emerging technologioes

b)

Use of Processors

c)

Using Sensitive Data

62.

Processing that will require DPIA

a)

Conduct a systematic and extensive evaluation of Natural persons

b)

Profiling

c)

Process a Larger Scale of Special Categories

d)

Process personal data relating to criminal convictions and offences

e)

Systematic Monitoring in Larger Scale

63.

Best practices for Data Protection Policies

a)

Use concise and understandable language

b)

Translate them

c)

Use metrics to show results

d)

Ensure the tasks are realistic, relevant and timely

64.

how is determined a LARGER SCALE of data subjects

a)

Volume

b)

Range

c)

Number of Data Subjects

d)

Duration

e)

Geographical extent of the processing

65.

Which appropriate safeguards allow large multinational companies to adopt a policy suite with rules for handling personal data?

a)

Binding corporate rules

b)

Standard Contractual Clauses

c)

Derogation

d)

Public Interest

e)

Adhoc contractual clauses

66.

True or false: Criteria for derogations are strict and should be interpreted narrowly

a)

True

b)

False

67.

DEROGATIONS

a)

Explicit Consent

b)

Necessary contract

c)

Public Interest-

and

Vital Interest

d)

Regiser of public informarion ( giving DS right to object)

e)

Legitimate interest of controller. (NON REPETITIVE and a certain #)

68.

Who does the GDPR task with promoting, monitoring and enforcing the GDPR?

a)

Supervisory authorities

b)

 

The European Data Protection Supervisor

 

69.

 

How many active participants will the European Data Protection Board have?

a)

1

b)

5

c)

7

d)

31

70.

 

Which of the following mechanisms facilitates the provision of relevant information between supervisory authorities?

a)

Cooperation  FOR REACH CONSENSUS

b)

Mutual  assistance

c)

Consistency mechanism FOR ADOP MEASURES AND ENSURE A GDPR CONSISTENT APLICATION

d)

 Urgency procedure PROVISIONAL MEAURUES INMEDIATE

71.

 

Which of the following mechanisms facilitates a specific collaborative process between supervisory authorities, the Commission and the European Data Protection Board for adopting certain measures and ensuring consistent GDPR application?

a)

Cooperation

b)

Consistency mechanism

c)

Dispute resolution

d)

Joint operations

72.

Cross Border Definition Elements

a)

Processing of Personal Data

b)

Activities of Establisments of

c)

More than 1 MS of a Controller or Processor In the EU

d)

The processor or controller is stablished in more than 1 member State

73.

If the processing is in fact cross-border processing, how does the controller identify the lead supervisory authority?

a)

If the organisation has a single establishment in the EU, then the lead supervisory authority will simply be that of the place of establishment.

b)

If the organisation has more than one establishment in the EU, then the lead supervisory authority will be that of the place of central administration.That is, unless

decisions about purposes, means and implementation of processing take place at a different location. If this is the case, then the SA of that location where the processing decisions take place will be the lead. This makes it possible for a company to have several lead SAs-if it conducts several cross-border activities whose related decisions take place in more than one location.

74.

mechanisms to support cooperation and consistency between supervisory authorities.

a)

cooperation

b)

mutual assistance

c)

Joint Operation

d)

Consistency mechanism

e)

Dispute resolution

75.

Roles of the European Data Protection Board

a)

Monitor for the correct application of the GDPR,

b)

ersee the consistency mechanism for ensuring a consistent approach to data protection by the various supervisory authorities.

c)

Issue guidance and advice to the Commission for personal data protection on a pan- European basis.

d)

And preside over the dispute-resolution process.

76.

·       Which types of laws should be considered when processing employees' personal data? Select all that apply.

a)

Local employment law

b)

EU data protection law

c)

Member state data protection law

 

77.

What must be provided to employees when processing their personal data?

a)

Opt-out

b)

Notice that their personal data will be processed

c)

Opt-in

d)

The supervisory authority's contact information

78.

True or false: Some employers may be required to consult with works councils and/or  trade unions to process employees' personal data.

a)

true

b)

false

79.

True or false: BYOD policies are designed to protect employees' personal data only.

a)

false

b)

true

80.

Alternatives to employee monitoring should always be considered first.

a)

true

b)

false

81.

 

 

What U.S. act requires companies to have a system in place to receive anonymous complaints about potential wrongdoing?

 

a)

Barnes-Laramey Act (BLAME)

b)

Washington's Whistle-blowing Act (WOW

c)

Young-Underthorn Act (YOU)

d)

Sarbanes-Oxley Act (SOX)

82.

Which of the following statements is true of private-sector entities that conduct  surveillance? Select all that apply.

a)

 

They include bodies such as national security agencies and law enforcement authorities.

b)

The surveillance they conduct must comply with national laws.

c)

The surveillance they conduct must be based on legitimate purposes.

83.

The e-Privacy Directive governs the processing of which types of data? Select all that apply.

a)

Location data

b)

Content data

c)

Traffic data

84.

True or false: Thee-Privacy Directive governs the processing of data through both private and public carriers and communications networks.

a)

True

b)

False

85.

·       Which of the following is not a data protection consideration associated with collecting personal data via CCTV?

a)

Prior checking

b)

Duration of the video

c)

Lawfulness

d)

Proportionality Individuals' rights

e)

Information provision

86.

Under the GDPR, individuals have the absolute right to object to any form of direct marketing at any time.

a)

TRUE

b)

FALSE

87.

Which of the following statements is true regarding direct marketing channels?

a)

For postal marketing, opt-in is required.

b)

 For telemarketing, opt-in is required.

c)

For business-to-consumer emailing and text-messaging, opt-in is required.

88.

True or false: Under the GDPR, web cookies qualify as personal data but IP addresses do not.

a)

True

b)

False

89.

·      When designing ways to actively collect personal data through a website, considerations may include:

a)

Collection limitation.

b)

Text Boxes

c)

Access to the data protection notice.

d)

Security obligation

90.

 

When may a cloud services supplier be considered a controller?

a)

When it determines substantial and essential elements of the means of processing; for example, data retention periods

b)

When it is GDPR compliant.

c)

When it processes data for its own purposes

d)

When it determines aspects of the processing outside the controller's instructions

91.

Even if the cloud provider is not directly subject to the GDPR, the cloud provider's customer in any case is not subject to it,

a)

True

b)

False