NEW
Font size
WorksheetsData Privacy
Total questions: 25
Worksheet time: 19mins
What is the purpose of the Data Protection Policy?
To describe data protection standards and applicable principles
To outline how to create data breaches
To focus on principles for data transfer
To define data population
Who is considered a Data Controller?
An employee of the Data Controller
A person who processes data on behalf of the Data Controller
A natural or legal person (or entity) who determines the purposes and manner of data processing
A person who stores data
What is the definition of Personal Data?
Data that can be processed electronically
Any information relating to an identifiable individual
Data stored in physical format
Data that is anonymized
Which of the following is a right of Data Subjects?
The right to rectify data
The right to transfer data
The right to encrypt data
The right to anonymize data
What is the main objective of the Personal Data Breach Policy?
To prevent data breaches only
To prevent data breaches and manage actual or suspected data breaches
To transfer personal data
To encrypt personal data
Which of the following are examples of Personal Data Breaches?
Unauthorized access to a system containing personal data
Loss or theft of an electronic device containing personal data
Corruption of personal data
All of the above
What is the role of the Data Protection Officer (DPO)?
To oversee and monitor the company's data protection strategy
To manage data transfers
To encrypt personal data
To store personal data
What is the purpose of the Personal Data Transfer Policy?
To establish principles that govern the transfer of personal data
To manage data breaches
To describe data protection standards
To define data processing
What is required for transferring personal data to a data processor?
Encryption of data
Anonymization of data
Deletion of data
Data processing agreements
What should be done in the event of a suspected or actual Personal Data Breach?
Contain the breach
Recover the personal data
Notify relevant parties
All of the above
Which of the following would constitute processing of Data Processing?
Obtaining, recording, or storing information
Erasing data
Disclosing and transmitting data
All of the above
What is the purpose of data protection training?
To transfer personal data
To anonymize personal data
To help employees understand their responsibilities regarding data protection
To encrypt personal data
What is the role of the Chief Information Officer (CIO) in the event of a data breach?
To notify customers
To oversee data protection strategy
To encrypt personal data
To manage and maintain data
Where can you find all our Data Privacy related policies?
Infobuzz
Cybervillage
GK Foods Website
GraceKennedy Limited’s website
What is the purpose of a Data Protection Impact Assessment?
To evaluate the origin, nature, particularity, and severity of risk
To encrypt personal data
To transfer personal data
To delete personal data
What is required for all personal data transfers?
Encryption of data
Anonymization of data
Deletion of data
Compliance with data protection laws of that jurisdiction
What is the definition of Data Transfer?
Encrypting data
Any information transferred from one location to another
Deleting data
Anonymizing data
What is the role of the Head of Corporate Communications in the event of a data breach?
To notify customers and the public
To manage and maintain data
To oversee data protection strategy
To encrypt personal data
When is Data Privacy Day?
January 27
January 28
January 29
January 30
What is the definition of Consent in the context of data protection?
Freely given, specific, informed, and unambiguous indication of the data subject's wishes
Encrypting data
Transferring data
Deleting data
What should you do if you receive an email from an unknown sender asking for personal information?
Reply to verify the sender’s identity
Delete the email or mark it as spam
Reply to the email by describing data protection standards to the sender
Share minimal information to stay safe
A Data Breach is best defined as:
A security incident affecting the confidentiality, integrity, or availability of data
Unauthorized access to a system containing personal data
Loss or theft of an electronic device containing personal data
All of the above
What is required for the collection and processing of personal data?
Transparency about the intended use of the personal data
Encryption of data
Anonymization of data
Deletion of data
What is the best practice for creating a strong password?
Use your name and birth year
Use a simple, short password for convenience
Use a mix of uppercase letters, lowercase letters, numbers, and symbols
Reuse passwords across multiple accounts
What is the name of our Privacy Mascot?
Private Locky
Privacy Peter
Lieutenant Lock
Privacy Pete
