Font size
WorksheetsData Protection
Total questions: 30
Worksheet time: 43mins
What is the primary purpose of data protection regulations?
To prevent all data breaches
To ensure data is processed fairly and lawfully
To allow organizations to share data freely
To standardize data storage methods globally
Which of the following is a core principle of the General Data Protection Regulation (GDPR)?
Unlimited data retention
Accountability
Optional data security measures
Processing without a legal basis
What is the role of a Data Custodian?
To determine the purposes and means of processing personal data
To provide legal advice on data protection compliance
To ensure the technical environment for data is secure and operational
To interact directly with data subjects regarding their rights
Which right do individuals have under many data protection laws regarding their personal data?
The right to demand public disclosure of all data about them
The right to unlimited data portability to any platform
The right to rectification (correction) of inaccurate data
The right to permanently delete all digital footprints
What is a 'data processor' in the context of data protection?
An individual who inputs data into a system
An entity that determines the purposes and means of processing personal data
An entity that processes personal data on behalf of a data controller
A person who breaches data security protocols
What does 'anonymization' mean in the context of data protection?
Storing data in a secure, encrypted format
Processing data quickly to avoid delays
The process of removing personally identifiable information from data
Making data available to the public without restrictions
Which of the following is a common security measure to protect personal data?
Using generic, easily guessable passwords for all accounts
Storing all data on publicly accessible cloud servers without encryption
Implementing strong encryption for data at rest and in transit
Sharing data with third parties without contractual agreements
Which of the following best describes 'data at rest'?
Data that is actively being transmitted over a network
Data that is stored on a physical or digital medium, such as a hard drive or database
Data that has been permanently deleted from all systems
Data that is being used by an application in active memory
Which of the following stages are typically part of a data lifecycle? (Select all that apply)
Data Collection
Data Hacking
Data Storage
Data Regulation
Data Usage
An identifiable natural person to whom personal data relates is referred to as a ___________.
Which of the following are primary responsibilities or roles of a data controller? (Select all that apply)
Processing personal data only on documented instructions from a processor
Determining the purposes and means of processing personal data
Ensuring a lawful basis for processing personal data
Implementing appropriate technical and organizational measures for data protection
Maintaining a public directory of all individuals globally
What does CCPA stand for?
California Consumer Protection Agency
California Confidentiality and Privacy Act
California Consumer Privacy Act
Californian Corporate Protection Authority
According to both GDPR and CCPA, which of the following best describes 'personal data' (or 'personal information')?
Only financial or health-related information
Data that is publicly available
Any information relating to an identified or identifiable natural person
Information that can only be identified by law enforcement
Which of the following are core principles of the General Data Protection Regulation (GDPR)? (Select all that apply)
Lawfulness, fairness, and transparency
Data monetization
Purpose limitation
Unlimited data retention
Data minimization
What is the primary data protection law currently in force in Eswatini (formerly Swaziland)?
The Eswatini Privacy Act of 2010
The Data Protection Act No. 5 of 2022
The Swaziland Information Security Decree
The African Union Data Protection Convention
A tech company based in Eswatini ( SethuTechnologies ) processes personal data on its computers located in Eswatini. This data includes information about its customers who reside in Germany. Based on this scenario, which data protection law(s) should this Eswatini company primarily comply with when processing its German customers' personal data? (Select all that apply)
The California Consumer Privacy Act (CCPA)
The Data Protection Act No. 5 of 2022 (Eswatini)
The Health Insurance Portability and Accountability Act (HIPAA)
The General Data Protection Regulation (GDPR)
Why is it important for organizations to have a clear data protection policy?
The principle of (a) ensures that only necessary data is collected.
(a) is the legal basis for processing data when the individual has agreed.
Data should not be kept longer than necessary, according to the (a) principle.
What are the potential consequences of failing to comply with data protection laws?
Why is it important to distinguish/classify data?
What are the Data the common classification types?
Public
Personal
Internal / Private
Confidential
Shared
Personal Data may include: (list only 2)?
A breach involving public data may be a Higher risk than one involving medical records.
TRUE
FALSE
A hospital in Mbabane collects patient health records for treatment purposes.
What legal basis allows them to process this sensitive data under Eswatini’s DPA?
Consent from the patient
Public interest
Commission authorization
Vital interests of the data subject
A local marketing firm wants to use customer email addresses collected during a promotion to send future advertisements.
What principle must they follow before doing so?
Retention limitation
Accuracy
Data minimisation
Purpose specification
An Eswatini-based e-commerce platform suffers a data breach exposing customer payment details.
What is their first obligation under the DPA?
Notify the Eswatini Communications Commission promptly
Issue a public apology
Delete all affected data
Notify the affected customers only
A citizen requests to see what personal data a telecom company holds about them.
What right are they exercising under Eswatini’s DPA?
A school stores student records digitally and wants to ensure compliance with the DPA.
Which security measure is most appropriate?
Limiting access to authorized staff
Using shared login credentials
Posting passwords on notice boards
Allowing open access to all teachers
