WorksheetsEXIN Privacy & Data Protection Foundation - Quiz 1
Total questions: 20
Worksheet time: 10mins
What is GDPR's primary purpose?
To restrict internet access
To unify data protection laws in the EU
To increase product marketing
To prevent financial fraud
What does "personal data" include?
Information about companies
Any data identifying an individual
Financial data only
Anonymous data
When did GDPR come into effect?
2008
2015
2018
2020
Which role ensures GDPR compliance in an organization?
Data Subject
Data Protection Officer
Marketing Manager
HR Representative
What is the 'right to be forgotten'?
A request to erase personal data
A right to access all global databases
An exemption from legal obligations
A right to anonymity
What is pseudonymization?
Complete anonymization of data
A process to identify data directly
Processing data so it cannot be linked to a person without additional information
Data theft prevention
Which of these is a lawful basis for processing data?
For curiosity
With clear consent
Without notifying the individual
For speculative purposes
What is the principle of 'data minimization'?
Collecting excessive data for all uses
Limiting data to what is necessary for a specific purpose
Keeping unnecessary copies of data
None of the above
Who is a 'data subject'?
An entity controlling data
An individual whose data is processed
A person who processes data for others
None of the above
What does a 'data breach' involve?
Loss of personal data security
Routine data maintenance
Automated decision-making
Sharing public information
What is 'accountability' in GDPR?
Shifting responsibility to others
Proving compliance with data protection laws
Ignoring data breaches
Documenting non-essential activities
Which countries must comply with GDPR?
EU countries only
All global countries
EU and EEA countries
None of the above
What is 'data portability'?
Moving data between personal devices
The right to receive and transfer data between controllers
Deleting old data
Encrypting all records
What should happen if a personal data breach occurs?
Ignore it
Notify the authorities within 72 hours
Inform only internal teams
Wait until the breach is resolved
Which category of data is considered 'sensitive'?
Publicly available data
Ethnic origin or biometric data
Marketing preferences
Employment history
What is 'privacy by design'?
A last-minute compliance strategy
Integrating privacy measures into systems from the start
Encrypting data only when required
Avoiding user data collection
What is a 'processor' under GDPR?
An individual owning the data
A party processing data on behalf of the controller
A supervisory authority
None of the above
What are 'binding corporate rules'?
Internal policies for managing data across organizations
Rules for hiring employees
A legal framework for marketing
External penalties for data breaches
What is the primary goal of a DPIA (Data Protection Impact Assessment)?
To ignore privacy risks
To identify and mitigate data protection risks in a project
To implement unlimited data retention policies
To delay project deadlines
What does 'lawfulness of processing' require?
Ignoring legal obligations
Ensuring all data processing has a valid legal basis
Keeping data unregulated
Deleting public records
