NEW
Font size
WorksheetsPersonal Information and Its Uses
Total questions: 79
Worksheet time: 40mins
What is the purpose of collecting information such as First Name, Middle Name, Last Name, Date of Birth, and Address about a person?
To create a personal profile for identification
To calculate someone's age
To determine someone's favorite color
To find someone's hobbies
Which of the following is NOT typically included in a basic personal information form?
First Name
Middle Name
Favorite Food
Date of Birth
Why might it be important to know someone's Date of Birth?
To send them a birthday card
To verify their age for legal purposes
To know their zodiac sign
To determine their favorite season
What could be a potential use of knowing someone's address?
To send them mail or packages
To find their favorite restaurant
To determine their travel preferences
To calculate their commute time
What are the procedures that organisations must follow in order to conform to legal requirements?
Conduct regular audits and comply with regulations.
Ignore legal requirements and focus on profits.
Follow outdated policies without updates.
Avoid documentation and transparency.
What are the principles of data protection?
Transparency, accountability, and security.
Ignoring user privacy and sharing data freely.
Storing data without encryption or safeguards.
Avoiding compliance with data protection laws.
What are the benefits and drawbacks of sharing data?
Sharing data improves collaboration but may lead to privacy concerns.
Sharing data has no drawbacks and is always beneficial.
Sharing data reduces collaboration and increases privacy concerns.
Sharing data is only beneficial for large organizations.
What are the impacts of the manufacturing process, upgrading, and removal of IT equipment?
They have no environmental impact.
They contribute to e-waste and environmental pollution.
They reduce the need for recycling.
They improve the lifespan of IT equipment.
Why is it important to create equal access to digital services?
To ensure everyone can benefit from technology advancements.
To limit access to technology for certain groups.
To reduce the use of digital services.
To increase competition among users.
Why is net neutrality important in the 21st century?
It ensures equal access to online content without discrimination.
It allows internet providers to prioritize certain websites.
It limits access to online content for certain users.
It reduces the speed of internet services.
What does a Use Policy do to protect a user and an organization?
It defines acceptable use of IT systems and prevents misuse.
It limits the use of IT systems to certain users only.
It allows unrestricted use of IT systems.
It reduces the need for IT security measures.
What are the principles of data protection?
Ensuring data is stored indefinitely without restrictions.
Protecting data from unauthorized access and ensuring its accuracy.
Allowing unrestricted sharing of data.
Limiting data access to only government organizations.
What are the laws that cover the use of computers and systems?
Laws that regulate the manufacturing of computers only.
Laws that ensure ethical use and prevent misuse of computers and systems.
Laws that limit the use of computers to certain industries.
Laws that promote unrestricted use of computers.
How are computer systems used to break laws?
By hacking, spreading malware, and unauthorized access to data.
By improving cybersecurity measures.
By reducing the need for legal regulations.
By promoting ethical use of technology.
What are the three key pieces of information needed for ID theft?
Name, address, and date of birth
Name, phone number, and email address
Address, social security number, and phone number
Date of birth, passport number, and credit card details
Why are name, address, and date of birth sufficient for fraudsters to commit ID theft?
They can use these details to create fake IDs and open bank accounts
These details are required for social media registration
Fraudsters use these details to hack into email accounts
These details are used to track someone's location
How can fraudsters obtain a date of birth from social networks if it is not explicitly listed in a profile?
By analyzing posts or comments related to birthdays
By hacking into the user's account
By contacting the user directly
By guessing based on the user's profile picture
What is the purpose of data protection?
To look after the personal data of people
To store data for companies
To delete unnecessary data
To share data with third parties
Which law covers data protection in the UK as of 2018?
The Privacy Act
The Data Protection Act (2018)
The Information Security Act
The Cybersecurity Act
What significant regulation was added to the UK Data Protection Act in 2018?
EU General Data Protection Regulation (GDPR)
EU Privacy Regulation
EU Cybersecurity Regulation
EU Information Sharing Regulation
What are two ways companies could misuse your data?
Selling data to third parties and using it for targeted advertising
Encrypting data and storing it securely
Sharing data with authorized personnel only
Using data for legitimate business purposes
What is one of the key requirements for organisations that collect personal data?
Collect data for any purpose they choose.
Ensure the data is accurate.
Collect as much data as possible, regardless of purpose.
Sell all collected data to third parties.
What type of data may not be collected by organisations?
Data necessary for a specific purpose.
Data that is not necessary for the specific purpose.
Data from user sign-up details.
Data purchased from third parties.
Where can organisations obtain data from?
Only from their own employees.
From third parties and user sign-up details.
From government databases.
From social media platforms exclusively.
What is the primary purpose of collecting personal data according to the guidelines?
To collect data for a specific purpose.
To collect data for marketing campaigns.
To collect data for resale to third parties.
To collect data for storing indefinitely.
Which of the following is NOT one of the six reasons for lawful processing?
Consent
Contract
Public interest
Legal obligation
What is one of the reasons for lawful processing that involves an agreement between two parties?
Consent
Contract
Public task
Vital interests
Which lawful processing reason is related to protecting someone's life or health?
Vital interests
Legal obligation
Public task
Legitimate interests
Which lawful processing reason is based on fulfilling a legal requirement?
Consent
Legal obligation
Public task
Legitimate interests
What does 'Consent' mean in the context of lawful processing?
A legal requirement to process data
An agreement given by the individual for their data to be processed
A task performed in the public interest
A contract between two parties
Which lawful processing reason involves performing a task in the public interest?
Public task
Legitimate interests
Contract
Vital interests
What does 'Legitimate interests' mean in the context of lawful processing?
A reason based on protecting someone's life
A reason based on the interests of the data controller or a third party
A reason based on fulfilling a legal requirement
A reason based on an agreement between two parties
Which lawful reason for data processing involves a person agreeing to their data being used?
Contract
Consent
Legal obligation
Public task
What lawful reason for data processing is required to meet the law?
Vital interests
Legal obligation
Legitimate interests
Consent
Which lawful reason for data processing is used to protect someone’s life?
Vital interests
Public task
Contract
Legitimate interests
What lawful reason for data processing is used for performing an official task?
Public task
Legal obligation
Consent
Vital interests
Which lawful reason for data processing involves a clear benefit to the user or company?
Legitimate interests
Contract
Vital interests
Public task
Which example corresponds to the lawful reason "Contract"?
A tick box to consent to receive a newsletter
A contract for buying a house
Keeping tax records
Processing customer data
What is an example of data processing under "Vital interests"?
A teacher gives a collapsed student’s name to a paramedic
A criminal court
Processing customer data
Keeping tax records
Which lawful reason for data processing is exemplified by "Keeping tax records"?
Legal obligation
Public task
Contract
Legitimate interests
What is an example of data processing under "Public task"?
A criminal court
A tick box to consent to receive a newsletter
Processing customer data
A contract for buying a house
Which lawful reason for data processing is exemplified by "Processing customer data"?
Legitimate interests
Vital interests
Consent
Public task
What is the specific purpose for collecting personal data in the given case?
To recommend health products to users.
To send newsletters to users.
To collect feedback on health products.
To track user activity on the website.
Which of the following data items are not part of the specific purpose for collecting data in the given form?
Current income.
Number of people in your family.
Username.
First name.
What action should the website take to ensure user consent for sending newsletters?
Add a checkbox for users to opt-in for newsletters.
Automatically enroll users for newsletters.
Send newsletters without user consent.
Add a mandatory field for newsletter subscription.
What is one of the requirements for storing data securely?
Data must be kept accurate and up to date.
Data must be shared freely with other countries.
Data must be stored indefinitely.
Customers must not be informed of data breaches.
How long should data be kept according to secure storage guidelines?
As long as possible.
Only as long as necessary.
Indefinitely.
Until customers request its deletion.
What must happen if a data breach occurs?
Customers must be informed within 72 hours.
Customers must be informed within 30 days.
Customers must not be informed.
Customers must be informed only if the breach is severe.
Under what condition can data be transferred to other countries?
If the other country can keep it protected.
If the other country requests it.
If the data is outdated.
If the data is encrypted.
What is the primary concern when personal data stored on devices is stolen from a law firm?
It is a violation of data protection laws.
It is a minor inconvenience with no legal consequences.
It is a breach of client confidentiality but not data protection laws.
It is a technical issue that can be ignored.
What should the law firm do immediately after discovering a data protection breach?
Notify the relevant authorities and affected clients.
Ignore the breach and continue operations.
Replace the stolen devices without further action.
Wait for the stolen items to be recovered before taking action.
Which of the following actions could have prevented the data protection breach in the case study?
Encrypting the data on the devices and securing them physically.
Leaving the devices unattended on the desk.
Storing personal data without encryption.
Relying on the assumption that theft is unlikely.
Why is it important for a law firm to protect personal data stored on devices?
To comply with data protection laws and maintain client trust.
To avoid minor inconveniences in daily operations.
To ensure devices are not stolen.
To prevent technical issues with the devices.
What is considered a reasonable level of protection for highly sensitive personal data in a locked room?
Encryption of the data
Leaving the door unlocked
Storing data without encryption
Not notifying clients of a breach
If encryption is not used and the door is not locked, what is the consequence for the data?
The data is sufficiently protected
The data is not sufficiently protected
The data becomes inaccessible
The data is automatically deleted
What must be done if a data breach occurs?
Ignore the breach
Notify any clients affected and remotely wipe stolen devices
Encrypt the data after the breach
Lock the room after the breach
Which act provides individuals with rights regarding their personal data?
The Freedom of Information Act (2000)
The Data Protection Act (2018)
The Equality Act (2010)
The Consumer Rights Act (2015)
What does the right to withdraw consent under the Data Protection Act (2018) allow you to do?
View data stored about you by organizations
Be removed from a mailing list
Make changes to inaccurate data
Delete your personal data
Under the Data Protection Act (2018), what does the right to be forgotten allow you to do?
View data stored about you by organizations
Withdraw consent for data usage
Delete your personal data
Make changes to inaccurate data
Which of the following is a right provided by the Data Protection Act (2018)?
The right to access public records
The right to view data stored about you by organizations
The right to request free services from organizations
The right to share data freely
What does the right to withdraw consent under the Data Protection Act (2018) allow you to do?
View data stored about you by organizations
Be removed from a mailing list
Make changes to inaccurate data
Delete your personal data
What are the penalties for breaching the Data Protection Act?
Issuing warnings to the organisation and ordering compliance
Imprisonment of the organisation's CEO
Revoking the organisation's license to operate
Shutting down the organisation permanently
What is the maximum fine for serious breaches of the Data Protection Act?
4% of company turnover or €20 million
10% of company turnover or €50 million
2% of company turnover or €10 million
5% of company turnover or €25 million
If Shell earns over £180 billion per year, what could their maximum fine be for breaching the Data Protection Act?
£7.2 billion
£18 billion
£4.5 billion
£2 billion
What is one of the rights people have regarding data collection?
People have the right to withdraw consent for data collection.
People have no right to update inaccurate data.
Data must be kept longer than necessary.
Fines can be 10% of company turnover.
What does the "right to be forgotten" mean in the context of data protection?
The right to have personal data erased when it is no longer necessary.
The right to keep all data indefinitely.
The right to share data freely without restrictions.
The right to update inaccurate data.
Which of the following is true about data breaches?
All data breaches result in a fine or prison sentence.
Data breaches are always lawful.
Data breaches can be sent with the lawful reason of "Vital Interests."
Data breaches have no consequences.
What is the maximum percentage of company turnover that fines can reach for data protection violations?
4%
10%
2%
5%
Which of the following statements is correct regarding advertising and data protection?
Advertising can be sent with the lawful reason of "Vital Interests."
Advertising can be sent without any lawful reason.
Advertising must always be sent with consent.
Advertising is not covered under data protection laws.
What is the primary purpose of cookies sent to a user's computer by websites?
To store data such as the contents of your shopping basket
To delete user data from the website
To prevent users from accessing the website
To block advertisements on the website
Which of the following is NOT a function of cookies on websites?
Remembering that you are logged into a social network
Tracking your activity
Targeting advertising to you
Encrypting your personal data
Why is user consent required for receiving cookies on websites?
To ensure users are aware of data collection practices
To allow websites to delete user data
To prevent users from accessing the website
To block advertisements on the website
Which of the following is an example of how cookies are used by websites?
Storing the contents of your shopping basket
Preventing access to certain pages
Encrypting user passwords
Blocking advertisements
What is transactional data?
Data created when people buy or sell something
Data stored in a database for future use
Data collected from social media platforms
Data generated by weather forecasting systems
What transactional data will a supermarket produce when you buy products?
A list of purchased items and their prices
A list of employees working in the supermarket
A list of nearby supermarkets
A list of weather conditions during the purchase
Where else can transactional data be produced apart from physical stores?
Online shopping
Social media platforms
Weather forecasting systems
School attendance records
State one law which is designed to protect personal data.
General Data Protection Regulation (GDPR)
Freedom of Information Act
Copyright Act
Environmental Protection Act
Identify one type of crime which may be committed if criminals obtain personal information.
Identity theft
Tax evasion
Trespassing
Vandalism
One action that Marriott International should take after discovering a data breach is:
Notify affected customers and authorities
Ignore the breach and continue operations
Delete all customer data permanently
Increase hotel prices to cover losses
