wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

Personal Information and Its Uses

Total questions: 79

Worksheet time: 40mins

Name
Class
Date
1.

What is the purpose of collecting information such as First Name, Middle Name, Last Name, Date of Birth, and Address about a person?

a)

To create a personal profile for identification

b)

To calculate someone's age

c)

To determine someone's favorite color

d)

To find someone's hobbies

2.

Which of the following is NOT typically included in a basic personal information form?

a)

First Name

b)

Middle Name

c)

Favorite Food

d)

Date of Birth

3.

Why might it be important to know someone's Date of Birth?

a)

To send them a birthday card

b)

To verify their age for legal purposes

c)

To know their zodiac sign

d)

To determine their favorite season

4.

What could be a potential use of knowing someone's address?

a)

To send them mail or packages

b)

To find their favorite restaurant

c)

To determine their travel preferences

d)

To calculate their commute time

5.

What are the procedures that organisations must follow in order to conform to legal requirements?

a)

Conduct regular audits and comply with regulations.

b)

Ignore legal requirements and focus on profits.

c)

Follow outdated policies without updates.

d)

Avoid documentation and transparency.

6.

What are the principles of data protection?

a)

Transparency, accountability, and security.

b)

Ignoring user privacy and sharing data freely.

c)

Storing data without encryption or safeguards.

d)

Avoiding compliance with data protection laws.

7.

What are the benefits and drawbacks of sharing data?

a)

Sharing data improves collaboration but may lead to privacy concerns.

b)

Sharing data has no drawbacks and is always beneficial.

c)

Sharing data reduces collaboration and increases privacy concerns.

d)

Sharing data is only beneficial for large organizations.

8.

What are the impacts of the manufacturing process, upgrading, and removal of IT equipment?

a)

They have no environmental impact.

b)

They contribute to e-waste and environmental pollution.

c)

They reduce the need for recycling.

d)

They improve the lifespan of IT equipment.

9.

Why is it important to create equal access to digital services?

a)

To ensure everyone can benefit from technology advancements.

b)

To limit access to technology for certain groups.

c)

To reduce the use of digital services.

d)

To increase competition among users.

10.

Why is net neutrality important in the 21st century?

a)

It ensures equal access to online content without discrimination.

b)

It allows internet providers to prioritize certain websites.

c)

It limits access to online content for certain users.

d)

It reduces the speed of internet services.

11.

What does a Use Policy do to protect a user and an organization?

a)

It defines acceptable use of IT systems and prevents misuse.

b)

It limits the use of IT systems to certain users only.

c)

It allows unrestricted use of IT systems.

d)

It reduces the need for IT security measures.

12.

What are the principles of data protection?

a)

Ensuring data is stored indefinitely without restrictions.

b)

Protecting data from unauthorized access and ensuring its accuracy.

c)

Allowing unrestricted sharing of data.

d)

Limiting data access to only government organizations.

13.

What are the laws that cover the use of computers and systems?

a)

Laws that regulate the manufacturing of computers only.

b)

Laws that ensure ethical use and prevent misuse of computers and systems.

c)

Laws that limit the use of computers to certain industries.

d)

Laws that promote unrestricted use of computers.

14.

How are computer systems used to break laws?

a)

By hacking, spreading malware, and unauthorized access to data.

b)

By improving cybersecurity measures.

c)

By reducing the need for legal regulations.

d)

By promoting ethical use of technology.

15.

What are the three key pieces of information needed for ID theft?

a)

Name, address, and date of birth

b)

Name, phone number, and email address

c)

Address, social security number, and phone number

d)

Date of birth, passport number, and credit card details

16.

Why are name, address, and date of birth sufficient for fraudsters to commit ID theft?

a)

They can use these details to create fake IDs and open bank accounts

b)

These details are required for social media registration

c)

Fraudsters use these details to hack into email accounts

d)

These details are used to track someone's location

17.

How can fraudsters obtain a date of birth from social networks if it is not explicitly listed in a profile?

a)

By analyzing posts or comments related to birthdays

b)

By hacking into the user's account

c)

By contacting the user directly

d)

By guessing based on the user's profile picture

18.

What is the purpose of data protection?

a)

To look after the personal data of people

b)

To store data for companies

c)

To delete unnecessary data

d)

To share data with third parties

19.

Which law covers data protection in the UK as of 2018?

a)

The Privacy Act

b)

The Data Protection Act (2018)

c)

The Information Security Act

d)

The Cybersecurity Act

20.

What significant regulation was added to the UK Data Protection Act in 2018?

a)

EU General Data Protection Regulation (GDPR)

b)

EU Privacy Regulation

c)

EU Cybersecurity Regulation

d)

EU Information Sharing Regulation

21.

What are two ways companies could misuse your data?

a)

Selling data to third parties and using it for targeted advertising

b)

Encrypting data and storing it securely

c)

Sharing data with authorized personnel only

d)

Using data for legitimate business purposes

22.

What is one of the key requirements for organisations that collect personal data?

a)

Collect data for any purpose they choose.

b)

Ensure the data is accurate.

c)

Collect as much data as possible, regardless of purpose.

d)

Sell all collected data to third parties.

23.

What type of data may not be collected by organisations?

a)

Data necessary for a specific purpose.

b)

Data that is not necessary for the specific purpose.

c)

Data from user sign-up details.

d)

Data purchased from third parties.

24.

Where can organisations obtain data from?

a)

Only from their own employees.

b)

From third parties and user sign-up details.

c)

From government databases.

d)

From social media platforms exclusively.

25.

What is the primary purpose of collecting personal data according to the guidelines?

a)

To collect data for a specific purpose.

b)

To collect data for marketing campaigns.

c)

To collect data for resale to third parties.

d)

To collect data for storing indefinitely.

26.

Which of the following is NOT one of the six reasons for lawful processing?

a)

Consent

b)

Contract

c)

Public interest

d)

Legal obligation

27.

What is one of the reasons for lawful processing that involves an agreement between two parties?

a)

Consent

b)

Contract

c)

Public task

d)

Vital interests

28.

Which lawful processing reason is related to protecting someone's life or health?

a)

Vital interests

b)

Legal obligation

c)

Public task

d)

Legitimate interests

29.

Which lawful processing reason is based on fulfilling a legal requirement?

a)

Consent

b)

Legal obligation

c)

Public task

d)

Legitimate interests

30.

What does 'Consent' mean in the context of lawful processing?

a)

A legal requirement to process data

b)

An agreement given by the individual for their data to be processed

c)

A task performed in the public interest

d)

A contract between two parties

31.

Which lawful processing reason involves performing a task in the public interest?

a)

Public task

b)

Legitimate interests

c)

Contract

d)

Vital interests

32.

What does 'Legitimate interests' mean in the context of lawful processing?

a)

A reason based on protecting someone's life

b)

A reason based on the interests of the data controller or a third party

c)

A reason based on fulfilling a legal requirement

d)

A reason based on an agreement between two parties

33.

Which lawful reason for data processing involves a person agreeing to their data being used?

a)

Contract

b)

Consent

c)

Legal obligation

d)

Public task

34.

What lawful reason for data processing is required to meet the law?

a)

Vital interests

b)

Legal obligation

c)

Legitimate interests

d)

Consent

35.

Which lawful reason for data processing is used to protect someone’s life?

a)

Vital interests

b)

Public task

c)

Contract

d)

Legitimate interests

36.

What lawful reason for data processing is used for performing an official task?

a)

Public task

b)

Legal obligation

c)

Consent

d)

Vital interests

37.

Which lawful reason for data processing involves a clear benefit to the user or company?

a)

Legitimate interests

b)

Contract

c)

Vital interests

d)

Public task

38.

Which example corresponds to the lawful reason "Contract"?

a)

A tick box to consent to receive a newsletter

b)

A contract for buying a house

c)

Keeping tax records

d)

Processing customer data

39.

What is an example of data processing under "Vital interests"?

a)

A teacher gives a collapsed student’s name to a paramedic

b)

A criminal court

c)

Processing customer data

d)

Keeping tax records

40.

Which lawful reason for data processing is exemplified by "Keeping tax records"?

a)

Legal obligation

b)

Public task

c)

Contract

d)

Legitimate interests

41.

What is an example of data processing under "Public task"?

a)

A criminal court

b)

A tick box to consent to receive a newsletter

c)

Processing customer data

d)

A contract for buying a house

42.

Which lawful reason for data processing is exemplified by "Processing customer data"?

a)

Legitimate interests

b)

Vital interests

c)

Consent

d)

Public task

43.

What is the specific purpose for collecting personal data in the given case?

a)

To recommend health products to users.

b)

To send newsletters to users.

c)

To collect feedback on health products.

d)

To track user activity on the website.

44.

Which of the following data items are not part of the specific purpose for collecting data in the given form?

a)

Current income.

b)

Number of people in your family.

c)

Username.

d)

First name.

45.

What action should the website take to ensure user consent for sending newsletters?

a)

Add a checkbox for users to opt-in for newsletters.

b)

Automatically enroll users for newsletters.

c)

Send newsletters without user consent.

d)

Add a mandatory field for newsletter subscription.

46.

What is one of the requirements for storing data securely?

a)

Data must be kept accurate and up to date.

b)

Data must be shared freely with other countries.

c)

Data must be stored indefinitely.

d)

Customers must not be informed of data breaches.

47.

How long should data be kept according to secure storage guidelines?

a)

As long as possible.

b)

Only as long as necessary.

c)

Indefinitely.

d)

Until customers request its deletion.

48.

What must happen if a data breach occurs?

a)

Customers must be informed within 72 hours.

b)

Customers must be informed within 30 days.

c)

Customers must not be informed.

d)

Customers must be informed only if the breach is severe.

49.

Under what condition can data be transferred to other countries?

a)

If the other country can keep it protected.

b)

If the other country requests it.

c)

If the data is outdated.

d)

If the data is encrypted.

50.

What is the primary concern when personal data stored on devices is stolen from a law firm?

a)

It is a violation of data protection laws.

b)

It is a minor inconvenience with no legal consequences.

c)

It is a breach of client confidentiality but not data protection laws.

d)

It is a technical issue that can be ignored.

51.

What should the law firm do immediately after discovering a data protection breach?

a)

Notify the relevant authorities and affected clients.

b)

Ignore the breach and continue operations.

c)

Replace the stolen devices without further action.

d)

Wait for the stolen items to be recovered before taking action.

52.

Which of the following actions could have prevented the data protection breach in the case study?

a)

Encrypting the data on the devices and securing them physically.

b)

Leaving the devices unattended on the desk.

c)

Storing personal data without encryption.

d)

Relying on the assumption that theft is unlikely.

53.

Why is it important for a law firm to protect personal data stored on devices?

a)

To comply with data protection laws and maintain client trust.

b)

To avoid minor inconveniences in daily operations.

c)

To ensure devices are not stolen.

d)

To prevent technical issues with the devices.

54.

What is considered a reasonable level of protection for highly sensitive personal data in a locked room?

a)

Encryption of the data

b)

Leaving the door unlocked

c)

Storing data without encryption

d)

Not notifying clients of a breach

55.

If encryption is not used and the door is not locked, what is the consequence for the data?

a)

The data is sufficiently protected

b)

The data is not sufficiently protected

c)

The data becomes inaccessible

d)

The data is automatically deleted

56.

What must be done if a data breach occurs?

a)

Ignore the breach

b)

Notify any clients affected and remotely wipe stolen devices

c)

Encrypt the data after the breach

d)

Lock the room after the breach

57.

Which act provides individuals with rights regarding their personal data?

a)

The Freedom of Information Act (2000)

b)

The Data Protection Act (2018)

c)

The Equality Act (2010)

d)

The Consumer Rights Act (2015)

58.

What does the right to withdraw consent under the Data Protection Act (2018) allow you to do?

a)

View data stored about you by organizations

b)

Be removed from a mailing list

c)

Make changes to inaccurate data

d)

Delete your personal data

59.

Under the Data Protection Act (2018), what does the right to be forgotten allow you to do?

a)

View data stored about you by organizations

b)

Withdraw consent for data usage

c)

Delete your personal data

d)

Make changes to inaccurate data

60.

Which of the following is a right provided by the Data Protection Act (2018)?

a)

The right to access public records

b)

The right to view data stored about you by organizations

c)

The right to request free services from organizations

d)

The right to share data freely

61.

What does the right to withdraw consent under the Data Protection Act (2018) allow you to do?

a)

View data stored about you by organizations

b)

Be removed from a mailing list

c)

Make changes to inaccurate data

d)

Delete your personal data

62.

What are the penalties for breaching the Data Protection Act?

a)

Issuing warnings to the organisation and ordering compliance

b)

Imprisonment of the organisation's CEO

c)

Revoking the organisation's license to operate

d)

Shutting down the organisation permanently

63.

What is the maximum fine for serious breaches of the Data Protection Act?

a)

4% of company turnover or €20 million

b)

10% of company turnover or €50 million

c)

2% of company turnover or €10 million

d)

5% of company turnover or €25 million

64.

If Shell earns over £180 billion per year, what could their maximum fine be for breaching the Data Protection Act?

a)

£7.2 billion

b)

£18 billion

c)

£4.5 billion

d)

£2 billion

65.

What is one of the rights people have regarding data collection?

a)

People have the right to withdraw consent for data collection.

b)

People have no right to update inaccurate data.

c)

Data must be kept longer than necessary.

d)

Fines can be 10% of company turnover.

66.

What does the "right to be forgotten" mean in the context of data protection?

a)

The right to have personal data erased when it is no longer necessary.

b)

The right to keep all data indefinitely.

c)

The right to share data freely without restrictions.

d)

The right to update inaccurate data.

67.

Which of the following is true about data breaches?

a)

All data breaches result in a fine or prison sentence.

b)

Data breaches are always lawful.

c)

Data breaches can be sent with the lawful reason of "Vital Interests."

d)

Data breaches have no consequences.

68.

What is the maximum percentage of company turnover that fines can reach for data protection violations?

a)

4%

b)

10%

c)

2%

d)

5%

69.

Which of the following statements is correct regarding advertising and data protection?

a)

Advertising can be sent with the lawful reason of "Vital Interests."

b)

Advertising can be sent without any lawful reason.

c)

Advertising must always be sent with consent.

d)

Advertising is not covered under data protection laws.

70.

What is the primary purpose of cookies sent to a user's computer by websites?

a)

To store data such as the contents of your shopping basket

b)

To delete user data from the website

c)

To prevent users from accessing the website

d)

To block advertisements on the website

71.

Which of the following is NOT a function of cookies on websites?

a)

Remembering that you are logged into a social network

b)

Tracking your activity

c)

Targeting advertising to you

d)

Encrypting your personal data

72.

Why is user consent required for receiving cookies on websites?

a)

To ensure users are aware of data collection practices

b)

To allow websites to delete user data

c)

To prevent users from accessing the website

d)

To block advertisements on the website

73.

Which of the following is an example of how cookies are used by websites?

a)

Storing the contents of your shopping basket

b)

Preventing access to certain pages

c)

Encrypting user passwords

d)

Blocking advertisements

74.

What is transactional data?

a)

Data created when people buy or sell something

b)

Data stored in a database for future use

c)

Data collected from social media platforms

d)

Data generated by weather forecasting systems

75.

What transactional data will a supermarket produce when you buy products?

a)

A list of purchased items and their prices

b)

A list of employees working in the supermarket

c)

A list of nearby supermarkets

d)

A list of weather conditions during the purchase

76.

Where else can transactional data be produced apart from physical stores?

a)

Online shopping

b)

Social media platforms

c)

Weather forecasting systems

d)

School attendance records

77.

State one law which is designed to protect personal data.

a)

General Data Protection Regulation (GDPR)

b)

Freedom of Information Act

c)

Copyright Act

d)

Environmental Protection Act

78.

Identify one type of crime which may be committed if criminals obtain personal information.

a)

Identity theft

b)

Tax evasion

c)

Trespassing

d)

Vandalism

79.

One action that Marriott International should take after discovering a data breach is:

a)

Notify affected customers and authorities

b)

Ignore the breach and continue operations

c)

Delete all customer data permanently

d)

Increase hotel prices to cover losses