PDPF Exam Questions & Answers
Privacy and Data Protection Foundation • Exin
100% money-back guarantee
Sample PDPF Questions
Practice with real exam-style questions, each with the verified correct answer and explanation.
Which of these options is an example of a data breach?
Here is a catch between the options ''Loss of personal data'' and ''Transfer of personal data outside the EU''.
A data breach is whenever something happens that has not been planned with the personal data, be it improper processing, improper sharing, loss of data, deletion, etc. That is, personal data must be used for a specific purpose, respecting the life cycle (from collection to exclusion), any situation that escapes this cycle must be reported as a data breach.
The transfer of personal data outside the EU can also be considered a violation if there is no authorization from the data subject and if the destination country does not offer legislation like the GDPR. Although there is no specific legislation, the Supervisory Authority can authorize the transfer of data provided that the company in the destination country accepts standard contractual clauses for the processing of this data.
Article 46 of GDPR
1. In the absence of a decision pursuant to Article 45(3), a controller or processor may transfer personal data to a third country or an international organisation only if the controller or processor has provided appropriate safeguards, and on condition that enforceable data subject rights and effective legal remedies for data subjects are available.
Article 58 of GDPR
3. Each supervisory authority shall have all of the following authorisation and advisory powers: to authorise contractual clauses referred to in point (a) of Article 46(3).
A company CEO travels to a meeting in another city. He takes a notebook with information about the company's new projects and acquisitions, which will be the subject of discussion at this meeting. These are the only data stored on the notebook.
The notebook accidentally falls into the hotel's pool and all data is lost.
What happened, considering the General Data Protection Regulation (GDPR)?
The purpose of GDPR is to protect personal data. In the case of this issue there was no loss of personal data, so it is not a data breach.
Important
A data breach is whenever something happens that has not been planned with the personal data, be it improper processing, improper sharing, loss of data, deletion, etc. That is, personal data must be used for a specific purpose, respecting the life cycle (from collection to exclusion), any situation that escapes this cycle must be reported as a data breach.
What is the purpose of Data Lifecycle Management (DLM)?
It aims to manage the flow of data throughout the life cycle, from collection, processing, sharing, storage and deletion.
Having the knowledge where the data travels, who is responsible, who has access, helps and a lot to implement security measures.
Someone regularly receives offers from a store where he purchased something five years ago. He wants the company to stop sending offers and to wipe his personal data.
Which aspect of the rights of a data subject in the General Data Protection Regulation (GDPR) requires the company to comply?
Which of the following options is provided for in the GDPR and can be made by Member States?
Recital 10 of GDPR states:
''Regarding the processing of personal data for compliance with a legal obligation, for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller, Member
States should be allowed to maintain or introduce national provisions to further specify the application of the rules of this Regulation.''
It also says: ''This Regulation also provides a margin of manoeuvre for Member States to specify its rules, including for the processing of special categories of personal data ('sensitive data').
However, this does not mean that Member States can approve a rule that goes against a GDPR guideline. Note that these national provisions are measures to increase the effectiveness of the law. Here is an example the case of Ireland where it was established that the DPO is responsible for data breaches, something that is not provided for in the GDPR.
Get access to all 149 verified questions with detailed answers.
Unlock All PDPF Questions