WorksheetsPCII DSS and GDPR
Total questions: 20
Worksheet time: 10mins
A restaurant stores customer credit card numbers on a spreadsheet on their office computer. They do not encrypt this data.
True
False
A European online store collects customer names and email addresses. They provide a clear privacy policy and obtain explicit consent for marketing emails.
True
False
A company experiences a data breach involving credit card information. They notify the affected cardholders and their acquiring bank within 72 hours.
True
False
A company operating in the EU collects employee biometric data without a legal basis or explicit consent.
True
False
A small business only processes a few credit card transactions per month. They are exempt from all PCI DSS requirements.
True
False
A website uses cookies to track user browsing behavior. They provide a cookie consent banner with an option to opt-out.
True
False
A company stores customer data in a cloud environment. They are not responsible for the security of that data.
True
False
A data subject in the EU requests access to their personal data held by a company. The company ignores the request.
True
False
An organization securely deletes all cardholder data after a transaction is completed.
True
False
A company that uses third party processors for credit card processing, does not need to worry about PCI DSS compliance.
True
False
What security standard focuses specifically on protecting cardholder data?
General Data Protection Regulatory (GDPR)
PCI DSS (Payment Card Industry Data Security Standard)
All of the above.
Which regulation aims to protect the personal data of individuals?
GDPR
PCI DSS
What does "PCI" stand for in PCI DSS?
Payment Card Industry
Payment Card Indexes
What does "GDPR" stand for?
General Data Protection Regulation
General Data Protection Regulatory
Which standard dictates requirements for organizations that handle credit card information?
PCI
PCI DSS
GDPR
Which regulation grants individuals rights such as the "right to be forgotten"?
PCI DSS
GDPR
GDRP
What type of data is the primary focus of PCI DSS?
Cardholder data
Supplier data
What type of data does GDPR primarily concern itself with?
Personal data
Financial Data
Legal Data
Which one is a legal regulation, PCI DSS or GDPR?
GDPR
PCI DSS
GDRP
What is the term for a person appointed by an organisation to oversee data protection responsibilities under GDPR?
Data Protection Officer
Data Privacy Officer
