Limited-Time Offer: Enjoy 50% Savings! Ends in 00h 00m 00s Coupon code: 50OFF
Skip to content

Free Exin Privacy and Data Protection Foundation PDPF Exam Questions

Page: 1 / 15 Total 149 questions

Want more questions? Get Premium Access.

Question 1

Which of the options below best represents data protection by design?

Correct Answer: A. It aims to incorporate security measures to protect data from the moment it is collected, throughout the processing and until its destruction at the end of the process
Explanation:

When we talk about protection by design, we are considering data protection throughout the data lifecycle, from collection, processing, sharing, storage and deletion.


Question 2

Regarding the Portability Law for data subjects, which option is correct?

Correct Answer: C. The data owner has the right to transmit his data to another controller without the controller that already has the personal data provided being able to prevent it.
Explanation:

Article 20 Right to data portability:

1. The data subject shall have the right to receive the personal data concerning him or her, which he or she has provided to a controller, in a structured, commonly used and machine-readable format and have the right to transmit those data to another controller without hindrance from the controller to which the personal data have been provided.


Question 3

What is the most important difference between the 95/46/EC and the GDPR?

Correct Answer: D. The GDPR applies to persons and organizations which process personal data within EEA member states. The scope of 95/46/EC is more restricted in this aspect. Section: (none) Explanation

Question 4

After appearing in a photo posted by a friend on a social network, a person felt embarrassed and decided that he wants the photo to be deleted.

According to the General Data Protection Regulation (GDPR), does that person have the right to delete this photo?

Correct Answer: B. True
Explanation:

GDPR does not apply to the use of personal data for domestic purposes, however in this example the controller is the Social Network, as it performs the processing of the photos. Therefore, the owner has the right to delete this photo.

For domestic purposes, data collection is not intended for professional or commercial purposes. Examples are the get-togethers of friends and family where we can collect names, phone numbers, e-mails to facilitate the organization, as well as taking pictures to record the moment. Now if you have a blog where you can record several moments with your friends and you monetize it in some way -- watch out! -- you are under the scope of GDPR.

Whereas Recital 18: ''This Regulation does not apply to the processing of personal data by a natural person in the course of a purely personal or household activity and thus with no connection to a professional or commercial activity. Personal or household activities could include correspondence and the holding of addresses, or social networking and online activity undertaken within the context of such activities. However, this Regulation applies to controllers or processors which provide the means for processing personal data for such personal or household activities.''


Question 5

When personal data are processed, who is ultimately responsible for demonstrating compliance with the GDPR?

Correct Answer: D. Controller Section: (none) Explanation
Explanation:

Controller. Correct. The controller is responsible for adequate data security measures and must be able to demonstrate compliance with the GDPR. (Literature:A, Chapter 2)

Data protection officer (DPO). Incorrect. The DPO has expert knowledge and assists the controller or processor to monitor internal compliance.

Processor. Incorrect. The processor is the one who processes personal data according to the instructions of the controller. The controller remains ultimately responsible though.

Supervisory authority. Incorrect. The controller needs to demonstrate compliance with the GDPR if requested by the supervisory authority.


Question 6

Which of the options below is classified as a personal data breach under the GDPR?

Correct Answer: A. Personal data processed without the consent of the controller.
Explanation:

Another option says: ''A server is attacked and exploited by a hacker'', however, here it does not provide information if that server contained personal data.

The other wrong option is: 'Strategic company data is mistakenly shared'. Strategic data is not personal data.

For these reasons, the correct option is ''Personal data processed without the consent of the controller''. Note: even if the processor has a contract that authorizes the processing of personal data on behalf of the controller, it cannot perform any treatment to which it was not previously authorized, nor can it sub-process without the knowledge and consent of the controller.


Question 7

According to the GDPR, what is a description of binding corporate rules (BCR)?

Correct Answer: B. A set of approved rules on personal data protection used by a group of enterprises
Explanation:

A decision on the safety of transferring personal data to a non-EEA country. Incorrect. This refers to adequacy decisions.

A measure to compensate for the lack of personal data protection in a third country. Incorrect. This refers to appropriate safeguards.

A set of agreements covering personal data transfers between non-EEA countries. Incorrect. The GDPR does not cover agreements between non-EEA countries.

A set of approved rules on personal data protection used by a group of enterprises. Correct. BCR are a set of rules approved by the supervisory authorities. (Literature: A, Chapter 3; GDPR Article 47)


Question 8

A company's director's notebook is accidentally wet, which permanently damages the equipment so that it cannot recover its data.

The lost data concerned the financial reports of the company. What happened in this case according to GDPR?

Correct Answer: C. A security incident
Explanation:

The lost reports did not contain personal data, in this case GDPR is not applicable and is a security incident.

Important

A data breach is whenever something that has not been planned with personal data happens, be it improper processing, improper sharing, loss of data, deletion, etc. In other words, personal data must be used for a specific purpose, respecting the life cycle of the same (from collection to exclusion), any situation that escapes this cycle must be reported as a data breach.


Question 9

The Traffic Department of a city wants to know how many cars travel daily in order to plan the number of spaces needed to implement a rotating parking system.

To do this, cameras were installed at strategic points. Through image recognition software it is possible to capture the license plate and know how many cars traveled in the city. A monthly report is issued with the average number of cars present each day.

Signs and posters were spread around the city informing drivers and citizens what is the purpose of processing and that the data will be stored for up to five years, for future comparison.

What basic principle of legitimate processing of personal data is being violated in this case?

Correct Answer: A. Personal data must be kept in a way that allows the identification of data subjects for a period not longer than necessary.
Explanation:

Here we have a very common catch in EXIN exams.

As stated ''monthly a report is issued''. Therefore, the report issued and with the average number of cars for each day is known, there is no longer a need to keep the license plate records. The information on the average number of cars per day is already sufficient for the planning of rotating parking as well as sufficient for a future comparison. So, there is no need to keep personal data stored for 5 years.

You may be wondering if a license plate is personal data. The answer is yes. Any information that makes it possible to identify a person is considered personal data.

A real and interesting example was a wife who identified her husband's car at a friend's house through Google Maps. The license plates on Google Maps are erased for security, but the car had a specific sticker. See that the wife gathered two pieces of information: car model and sticker, to identify her husband. In isolation neither of these two is a personal data, but together they become, because it was possible to identify it.

Luckily for his wife, who discovered his affair with her friend.


Question 10

According to the GDPR, for which situations should a Data Protection Impact Assessment (DPIA) be conducted?

Correct Answer: A. For all projects that include technologies or processes that require data protection