NEW
Font size
WorksheetsGDPR Multiple-Choice Questions
Total questions: 20
Worksheet time: 10mins
Which of the following is NOT a lawful basis for processing personal data under GDPR?
Consent
Contractual necessity
Legitimate interests
Public curiosity
Under GDPR, what is the maximum fine for the most serious infringements?
€10 million or 2% of global turnover
€20 million or 4% of global turnover
€50 million or 10% of global turnover
€100 million or 5% of global turnover
Which article of GDPR defines the right to data portability?
Article 15
Article 17
Article 20
Article 25
What is the time limit for a Data Controller to notify a Data Protection Authority about a personal data breach?
24 hours
48 hours
72 hours
7 days
Which of the following is NOT considered personal data under GDPR?
IP address
Cookie identifiers
Company registration number
Biometric data
What is the main role of a Data Protection Officer (DPO)?
To manage marketing campaigns
To ensure compliance with GDPR within an organization
To handle customer complaints
To audit financial statements
Which of the following is a key principle of GDPR?
Data minimization
Data maximization
Data monetization
Data centralization
Under GDPR, how long can personal data be stored?
Indefinitely
Until the data subject requests deletion
As long as necessary for the purpose it was collected
Exactly 5 years
Which of the following is a right granted to data subjects under GDPR?
Right to be forgotten
Right to ignore data processing
Right to unlimited data access
Right to data ownership
What does the GDPR require for consent to be valid?
It must be freely given, specific, informed, and unambiguous
It must be implied through user inactivity
It must be given once and is valid indefinitely
It must be verbal only
Which GDPR article covers Data Protection Impact Assessments (DPIAs)?
Article 25
Article 30
Article 35
Article 40
Which of the following is NOT a responsibility of a Data Processor under GDPR?
Processing data only on instructions from the Data Controller
Reporting data breaches to the Data Controller
Determining the purposes of data processing
Implementing appropriate technical and organizational measures
What is the principle of 'Privacy by Design'?
Integrating data protection into processing activities from the start
Designing privacy policies after data collection
Designing websites with privacy notices only
Outsourcing privacy management to third parties
Which of the following is TRUE about cross-border data transfers under GDPR?
They are allowed without restrictions anywhere in the world
They require adequate safeguards or specific conditions to be met
They are banned completely outside the EU
They only require data subject consent
Which of the following is NOT a valid GDPR data subject right?
Right to rectification
Right to restriction of processing
Right to data monetization
Right to object
Which of the following is an example of sensitive personal data under GDPR?
Email address
Political opinions
Job title
IP address
Who is responsible for appointing a Data Protection Officer?
The Data Protection Authority
The Data Controller or Data Processor, if required
The data subjects
The European Commission
Which GDPR article requires documentation of processing activities?
Article 30
Article 32
Article 34
Article 36
What does the 'right to erasure' allow data subjects to do?
Request deletion of their personal data under certain conditions
Request data to be transferred to another controller
Request access to their personal data
Request correction of inaccurate data
Which of the following is NOT a technical measure recommended by GDPR to secure personal data?
Encryption
Pseudonymization
Data replication without controls
Access controls
