NEW
Font size
WorksheetsQuiz Privacy and Personal Data
Total questions: 30
Worksheet time: 15mins
A mobile fitness app asks users to grant access to GPS, contacts, and microphone. The user only wants step tracking and denies other permissions. The app refuses to function unless all permissions are granted. Which privacy principle is primarily being violated?
Data minimization
Accountability
Storage limitation
Data accuracy
Right to portability
A university collects student phone numbers for academic notifications. Later, marketing teams use them to send promotional messages without informing students. What is the main issue?
Data breach
Lawful basis misuse
Insecure storage
Right to erasure violation
Access control failure
A hospital stores HIV patient records in an unencrypted spreadsheet accessible to interns. No breach has occurred yet. What is the risk classification?
Low risk because there's no breach
High risk due to sensitive data and poor security
Medium risk because interns are trusted
No risk because only internal staff can see it
Risk only exists if data is leaked externally
A new social media app sets all accounts as publicly visible until manually changed by users. Many users are unaware and post sensitive content publicly. Which design principle was not applied?
Integrity and confidentiality
Privacy by Design
Data portability
Privacy by Default
Right to restrict processing
A fintech company discovers a data breach exposing 120,000 customer IDs. They decide to investigate quietly for 3 months before informing users. Which legal obligation was violated?
Purpose limitation
Storage limitation
72-hour breach notification rule
DPIA requirement
Minimization principle
A dataset with age, job role, and city is published for research. One user is the only female cybersecurity lecturer in a small town. This case violates which principle?
Data accuracy
Aggregation
Anonymization failure
Consent invalidity
Lawful basis selection
A former employee requests deletion of their profile. Company refuses, saying data is still useful for analytics. Which right is ignored?
Access
Portability
Rectification
Erasure
Restriction
A research lab adds random noise to student GPA statistics before publishing results. Individual GPA cannot be traced. Which privacy technology is being applied?
Encryption at rest
Differential Privacy
VPN tunneling
Access control list
Pseudonymization only
An e-commerce platform keeps customer transaction records indefinitely 'in case they are needed someday.' Which principle is violated?
Fair processing
Storage limitation
Purpose limitation
Right to object
Accuracy
A website uses tracking cookies for advertising but does not show a consent banner. Data is collected silently. Which legal element is missing?
Lawful basis documentation
Explicit consent
Controller registration
Encryption key rotation
DPIA approval
A university contracts a cloud storage vendor. A breach happens inside the vendor. Students blame the university. Who remains legally responsible for user data?
The cloud vendor only
The students using the app
Both controller and processor
The university as controller
Government regulator
A music app hides the 'Reject All' button under multiple menus but shows 'Accept All' instantly. This design violates:
Data portability
Consent fairness
Encryption standard
Accuracy requirement
Storage limitation
A student accidentally uploads a transcript to a public GitHub repo. The file includes name and NIM. This situation is best described as:
Data minimization issue
Unintentional data breach
PIBA conflict
Differential privacy failure
Legal public access
A keyboard app improves prediction accuracy without sending raw keystrokes to the server. Which method is used?
Hashing
Federated Learning
TLS encryption
Data aggregation
Key escrow
A bank refuses to delete customer loan history despite a deletion request. Why is this valid?
User consent was permanent
Legal obligation overrides erasure
Storage limitation is ignored
Bank owns the data
Contract basis no longer applies
A government deploys AI face recognition in public spaces. Before rollout, what must be performed?
Cookie audit
DPIA
Key rotation
Penetration test only
User self-assessment
A patient requests access to medical records but hospital refuses without reason. Which harm aligns with Solove’s taxonomy?
Surveillance
Exclusion
Blackmail
Exposure
Aggregation
A company stores payment info encrypted, but uses CCTV in office without employee notice. What is true?
Security controls always guarantee privacy
Privacy violation can occur even with security
CCTV stops cyber attacks
Encryption removes legal responsibility
No violation if no breach
Research team replaces names with codes (User01…). But separate file linking codes to names exists. Which classification applies?
Fully anonymous
Pseudonymized data
Data deleted
Public domain information
Random synthetic dataset
A game collects voice recordings from children without parental consent. Which legal breach is most severe?
Cookie policy violation
Child data protection failure
Data accuracy issue
DPIA not required
Storage redundancy
A website states “We do not share data,” but secretly sells email lists to advertisers. Which element is broken?
Transparency & honesty
Data minimization
Portability
Encryption
Consent age verification
A student finds their GPA recorded incorrectly in the university portal and requests correction. What right applies?
Right to restrict
Right to access
Right to rectify inaccurate data
Right to compensation
Right to deny public interest
A company sends Indonesian user data to servers abroad without safeguards or contract clauses. Which risk is highest?
Performance bottleneck
PDP non-compliance
Extra encryption cost
Duplicate storage
AI bias
A ride-hailing app stores only city-level location data instead of exact coordinates for analytics. This shows:
AI optimization
Privacy by Design & Minimization
Data monetization strategy
Dark pattern optimization
Rights restriction
A retail store uses CCTV to prevent theft. No facial recognition is used. Legal basis likely relies on:
Consent
Contract
Legitimate Interest
Public task
Erasure
A staff member copies student data to a personal USB for convenience. Which violation occurred first?
Data portability
Unauthorized access & processing
Lawful basis confusion
Public interest override
Research exemption
A user objects to being profiled for personalized ads but company continues. Which law right is violated?
Portability
Object/Opt-out
Accuracy
Retention
Security
A school collects student records and hires a vendor only to store data securely. Who is the Data Processor?
The vendor
The school
Students
Government
Parents
An API returning user profiles lacks authentication. Anyone can access personal details. This is primarily a failure of:
Purpose limitation
Access control security
Consent management
Aggregation
Pseudonymization
After a breach, although passwords aren't leaked, browsing history and private search logs are published. What injury type applies?
Exposure & reputational harm
Storage limitation failure only
Harmless breach
Rights to portability violation
No impact without financial loss
