wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Data Protection

Total questions: 30

Worksheet time: 43mins

Name
Class
Date
1.

What is the primary purpose of data protection regulations?

a)

To prevent all data breaches

b)

To ensure data is processed fairly and lawfully

c)

To allow organizations to share data freely

d)

To standardize data storage methods globally

2.

Which of the following is a core principle of the General Data Protection Regulation (GDPR)?

a)

Unlimited data retention

b)

Accountability

c)

Optional data security measures

d)

Processing without a legal basis

3.

What is the role of a Data Custodian?

a)

To determine the purposes and means of processing personal data

b)

To provide legal advice on data protection compliance

c)

To ensure the technical environment for data is secure and operational

d)

To interact directly with data subjects regarding their rights

4.

Which right do individuals have under many data protection laws regarding their personal data?

a)

The right to demand public disclosure of all data about them

b)

The right to unlimited data portability to any platform

c)

The right to rectification (correction) of inaccurate data

d)

The right to permanently delete all digital footprints

5.

What is a 'data processor' in the context of data protection?

a)

An individual who inputs data into a system

b)

An entity that determines the purposes and means of processing personal data

c)

An entity that processes personal data on behalf of a data controller

d)

A person who breaches data security protocols

6.

What does 'anonymization' mean in the context of data protection?

a)

Storing data in a secure, encrypted format

b)

Processing data quickly to avoid delays

c)

The process of removing personally identifiable information from data

d)

Making data available to the public without restrictions

7.

Which of the following is a common security measure to protect personal data?

a)

Using generic, easily guessable passwords for all accounts

b)

Storing all data on publicly accessible cloud servers without encryption

c)

Implementing strong encryption for data at rest and in transit

d)

Sharing data with third parties without contractual agreements

8.

Which of the following best describes 'data at rest'?

a)

Data that is actively being transmitted over a network

b)

Data that is stored on a physical or digital medium, such as a hard drive or database

c)

Data that has been permanently deleted from all systems

d)

Data that is being used by an application in active memory

9.

Which of the following stages are typically part of a data lifecycle? (Select all that apply)

a)

Data Collection

b)

Data Hacking

c)

Data Storage

d)

Data Regulation

e)

Data Usage

10.

An identifiable natural person to whom personal data relates is referred to as a ___________.

4 lines
11.

Which of the following are primary responsibilities or roles of a data controller? (Select all that apply)

a)

Processing personal data only on documented instructions from a processor

b)

Determining the purposes and means of processing personal data

c)

Ensuring a lawful basis for processing personal data

d)

Implementing appropriate technical and organizational measures for data protection

e)

Maintaining a public directory of all individuals globally

12.

What does CCPA stand for?

a)

California Consumer Protection Agency

b)

California Confidentiality and Privacy Act

c)

California Consumer Privacy Act

d)

Californian Corporate Protection Authority

13.

According to both GDPR and CCPA, which of the following best describes 'personal data' (or 'personal information')?

a)

Only financial or health-related information

b)

Data that is publicly available

c)

Any information relating to an identified or identifiable natural person

d)

Information that can only be identified by law enforcement

14.

Which of the following are core principles of the General Data Protection Regulation (GDPR)? (Select all that apply)

a)

Lawfulness, fairness, and transparency

b)

Data monetization

c)

Purpose limitation

d)

Unlimited data retention

e)

Data minimization

15.

What is the primary data protection law currently in force in Eswatini (formerly Swaziland)?

a)

The Eswatini Privacy Act of 2010

b)

The Data Protection Act No. 5 of 2022

c)

The Swaziland Information Security Decree

d)

The African Union Data Protection Convention

16.

A tech company based in Eswatini ( SethuTechnologies ) processes personal data on its computers located in Eswatini. This data includes information about its customers who reside in Germany. Based on this scenario, which data protection law(s) should this Eswatini company primarily comply with when processing its German customers' personal data? (Select all that apply)

a)

The California Consumer Privacy Act (CCPA)

b)

The Data Protection Act No. 5 of 2022 (Eswatini)

c)

The Health Insurance Portability and Accountability Act (HIPAA)

d)

The General Data Protection Regulation (GDPR)

17.
  1. Why is it important for organizations to have a clear data protection policy?

4 lines
18.

The principle of (a)   ensures that only necessary data is collected.

19.

(a)   is the legal basis for processing data when the individual has agreed.

20.

Data should not be kept longer than necessary, according to the (a)   principle.

21.

What are the potential consequences of failing to comply with data protection laws?

4 lines
22.

Why is it important to distinguish/classify data?

4 lines
23.

What are the Data the common classification types?

a)

Public

b)

Personal

c)

Internal / Private

d)

Confidential

e)

Shared

24.

Personal Data may include: (list only 2)?

4 lines
25.

A breach involving public data may be a Higher risk than one involving medical records.

a)

TRUE

b)

FALSE

26.

A hospital in Mbabane collects patient health records for treatment purposes.

26.

What legal basis allows them to process this sensitive data under Eswatini’s DPA?

a)
  • Consent from the patient

b)
  • Public interest

c)

Commission authorization

d)
  • Vital interests of the data subject

27.

A local marketing firm wants to use customer email addresses collected during a promotion to send future advertisements.

27.

What principle must they follow before doing so?

a)
  • Retention limitation

b)
  • Accuracy

c)
  • Data minimisation

d)

Purpose specification

28.

An Eswatini-based e-commerce platform suffers a data breach exposing customer payment details.

28.

What is their first obligation under the DPA?

a)

Notify the Eswatini Communications Commission promptly

b)
  • Issue a public apology

c)
  • Delete all affected data

d)
  • Notify the affected customers only

29.

A citizen requests to see what personal data a telecom company holds about them.

29.

What right are they exercising under Eswatini’s DPA?

4 lines
30.

A school stores student records digitally and wants to ensure compliance with the DPA.

30.

Which security measure is most appropriate?

a)

Limiting access to authorized staff

b)
  • Using shared login credentials

c)
  • Posting passwords on notice boards

d)
  • Allowing open access to all teachers