wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

EXIN Privacy & Data Protection Foundation - Quiz 1

Total questions: 20

Worksheet time: 10mins

Name
Class
Date
1.

What is GDPR's primary purpose?

a)

To restrict internet access

b)

To unify data protection laws in the EU

c)

To increase product marketing

d)

To prevent financial fraud

2.

What does "personal data" include?

a)

Information about companies

b)

Any data identifying an individual

c)

Financial data only

d)

Anonymous data

3.

When did GDPR come into effect?

a)

2008

b)

2015

c)

2018

d)

2020

4.

Which role ensures GDPR compliance in an organization?

a)

Data Subject

b)

Data Protection Officer

c)

Marketing Manager

d)

HR Representative

5.

What is the 'right to be forgotten'?

a)

A request to erase personal data

b)

A right to access all global databases

c)

An exemption from legal obligations

d)

A right to anonymity

6.

What is pseudonymization?

a)

Complete anonymization of data

b)

A process to identify data directly

c)

Processing data so it cannot be linked to a person without additional information

d)

Data theft prevention

7.

Which of these is a lawful basis for processing data?

a)

For curiosity

b)

With clear consent

c)

Without notifying the individual

d)

For speculative purposes

8.

What is the principle of 'data minimization'?

a)

Collecting excessive data for all uses

b)

Limiting data to what is necessary for a specific purpose

c)

Keeping unnecessary copies of data

d)

None of the above

9.

Who is a 'data subject'?

a)

An entity controlling data

b)

An individual whose data is processed

c)

A person who processes data for others

d)

None of the above

10.

What does a 'data breach' involve?

a)

Loss of personal data security

b)

Routine data maintenance

c)

Automated decision-making

d)

Sharing public information

11.

What is 'accountability' in GDPR?

a)

Shifting responsibility to others

b)

Proving compliance with data protection laws

c)

Ignoring data breaches

d)

Documenting non-essential activities

12.

Which countries must comply with GDPR?

a)

EU countries only

b)

All global countries

c)

EU and EEA countries

d)

None of the above

13.

What is 'data portability'?

a)

Moving data between personal devices

b)

The right to receive and transfer data between controllers

c)

Deleting old data

d)

Encrypting all records

14.

What should happen if a personal data breach occurs?

a)

Ignore it

b)

Notify the authorities within 72 hours

c)

Inform only internal teams

d)

Wait until the breach is resolved

15.

Which category of data is considered 'sensitive'?

a)

Publicly available data

b)

Ethnic origin or biometric data

c)

Marketing preferences

d)

Employment history

16.

What is 'privacy by design'?

a)

A last-minute compliance strategy

b)

Integrating privacy measures into systems from the start

c)

Encrypting data only when required

d)

Avoiding user data collection

17.

What is a 'processor' under GDPR?

a)

An individual owning the data

b)

A party processing data on behalf of the controller

c)

A supervisory authority

d)

None of the above

18.

What are 'binding corporate rules'?

a)

Internal policies for managing data across organizations

b)

Rules for hiring employees

c)

A legal framework for marketing

d)

External penalties for data breaches

19.

What is the primary goal of a DPIA (Data Protection Impact Assessment)?

a)

To ignore privacy risks

b)

To identify and mitigate data protection risks in a project

c)

To implement unlimited data retention policies

d)

To delay project deadlines

20.

What does 'lawfulness of processing' require?

a)

Ignoring legal obligations

b)

Ensuring all data processing has a valid legal basis

c)

Keeping data unregulated

d)

Deleting public records