wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

GDPR Multiple-Choice Questions

Total questions: 20

Worksheet time: 10mins

Name
Class
Date
1.

Which of the following is NOT a lawful basis for processing personal data under GDPR?

a)

Consent

b)

Contractual necessity

c)

Legitimate interests

d)

Public curiosity

2.

Under GDPR, what is the maximum fine for the most serious infringements?

a)

€10 million or 2% of global turnover

b)

€20 million or 4% of global turnover

c)

€50 million or 10% of global turnover

d)

€100 million or 5% of global turnover

3.

Which article of GDPR defines the right to data portability?

a)

Article 15

b)

Article 17

c)

Article 20

d)

Article 25

4.

What is the time limit for a Data Controller to notify a Data Protection Authority about a personal data breach?

a)

24 hours

b)

48 hours

c)

72 hours

d)

7 days

5.

Which of the following is NOT considered personal data under GDPR?

a)

IP address

b)

Cookie identifiers

c)

Company registration number

d)

Biometric data

6.

What is the main role of a Data Protection Officer (DPO)?

a)

To manage marketing campaigns

b)

To ensure compliance with GDPR within an organization

c)

To handle customer complaints

d)

To audit financial statements

7.

Which of the following is a key principle of GDPR?

a)

Data minimization

b)

Data maximization

c)

Data monetization

d)

Data centralization

8.

Under GDPR, how long can personal data be stored?

a)

Indefinitely

b)

Until the data subject requests deletion

c)

As long as necessary for the purpose it was collected

d)

Exactly 5 years

9.

Which of the following is a right granted to data subjects under GDPR?

a)

Right to be forgotten

b)

Right to ignore data processing

c)

Right to unlimited data access

d)

Right to data ownership

10.

What does the GDPR require for consent to be valid?

a)

It must be freely given, specific, informed, and unambiguous

b)

It must be implied through user inactivity

c)

It must be given once and is valid indefinitely

d)

It must be verbal only

11.

Which GDPR article covers Data Protection Impact Assessments (DPIAs)?

a)

Article 25

b)

Article 30

c)

Article 35

d)

Article 40

12.

Which of the following is NOT a responsibility of a Data Processor under GDPR?

a)

Processing data only on instructions from the Data Controller

b)

Reporting data breaches to the Data Controller

c)

Determining the purposes of data processing

d)

Implementing appropriate technical and organizational measures

13.

What is the principle of 'Privacy by Design'?

a)

Integrating data protection into processing activities from the start

b)

Designing privacy policies after data collection

c)

Designing websites with privacy notices only

d)

Outsourcing privacy management to third parties

14.

Which of the following is TRUE about cross-border data transfers under GDPR?

a)

They are allowed without restrictions anywhere in the world

b)

They require adequate safeguards or specific conditions to be met

c)

They are banned completely outside the EU

d)

They only require data subject consent

15.

Which of the following is NOT a valid GDPR data subject right?

a)

Right to rectification

b)

Right to restriction of processing

c)

Right to data monetization

d)

Right to object

16.

Which of the following is an example of sensitive personal data under GDPR?

a)

Email address

b)

Political opinions

c)

Job title

d)

IP address

17.

Who is responsible for appointing a Data Protection Officer?

a)

The Data Protection Authority

b)

The Data Controller or Data Processor, if required

c)

The data subjects

d)

The European Commission

18.

Which GDPR article requires documentation of processing activities?

a)

Article 30

b)

Article 32

c)

Article 34

d)

Article 36

19.

What does the 'right to erasure' allow data subjects to do?

a)

Request deletion of their personal data under certain conditions

b)

Request data to be transferred to another controller

c)

Request access to their personal data

d)

Request correction of inaccurate data

20.

Which of the following is NOT a technical measure recommended by GDPR to secure personal data?

a)

Encryption

b)

Pseudonymization

c)

Data replication without controls

d)

Access controls