wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

PCII DSS and GDPR

Total questions: 20

Worksheet time: 10mins

Name
Class
Date
1.

A restaurant stores customer credit card numbers on a spreadsheet on their office computer. They do not encrypt this data.

a)

True

b)

False

2.

A European online store collects customer names and email addresses. They provide a clear privacy policy and obtain explicit consent for marketing emails.

a)

True

b)

False

3.

A company experiences a data breach involving credit card information. They notify the affected cardholders and their acquiring bank within 72 hours.

a)

True

b)

False

4.

A company operating in the EU collects employee biometric data without a legal basis or explicit consent.

a)

True

b)

False

5.

A small business only processes a few credit card transactions per month. They are exempt from all PCI DSS requirements.

a)

True

b)

False

6.

A website uses cookies to track user browsing behavior. They provide a cookie consent banner with an option to opt-out.

a)

True

b)

False

7.

A company stores customer data in a cloud environment. They are not responsible for the security of that data.

a)

True

b)

False

8.

A data subject in the EU requests access to their personal data held by a company. The company ignores the request.

a)

True

b)

False

9.

An organization securely deletes all cardholder data after a transaction is completed.

a)

True

b)

False

10.

A company that uses third party processors for credit card processing, does not need to worry about PCI DSS compliance.

a)

True

b)

False

11.

What security standard focuses specifically on protecting cardholder data?

a)

General Data Protection Regulatory (GDPR)

b)

PCI DSS (Payment Card Industry Data Security Standard)

c)

All of the above.

12.

Which regulation aims to protect the personal data of individuals?

a)

GDPR

b)

PCI DSS

13.

What does "PCI" stand for in PCI DSS?

a)

Payment Card Industry

b)

Payment Card Indexes

14.

What does "GDPR" stand for?

a)

General Data Protection Regulation

b)

General Data Protection Regulatory

15.

Which standard dictates requirements for organizations that handle credit card information?

a)

PCI

b)

PCI DSS

c)

GDPR

16.

Which regulation grants individuals rights such as the "right to be forgotten"?

a)

PCI DSS

b)

GDPR

c)

GDRP

17.

What type of data is the primary focus of PCI DSS?

a)

Cardholder data

b)

Supplier data

18.

What type of data does GDPR primarily concern itself with?

a)

Personal data

b)

Financial Data

c)

Legal Data

19.

Which one is a legal regulation, PCI DSS or GDPR?

a)

GDPR

b)

PCI DSS

c)

GDRP

20.

What is the term for a person appointed by an organisation to oversee data protection responsibilities under GDPR?

a)

Data Protection Officer

b)

Data Privacy Officer