SCENARIO Please use the following to answer the next question: ABC Hotel Chain and XYZ Travel Agency are U.S.-based multinational companies. They use an internet-based common platform for collecting and sharing their customer data with each other, in order to integrate their marketing efforts. Additionally, they agree on the data to be stored, how reservations will be booked and confirmed, and who has access to the stored data. Mike, an EU resident, has booked travel itineraries in the past through XYZ Travel Agency to stay at ABC Hotel Chain's locations. XYZ Travel Agency offers a rewards program that allows customers to sign up to accumulate points that can later be redeemed for free travel. Mike has signed the agreement to be a rewards program member. Now Mike wants to know what personal information the company holds about him. He sends an email requesting access to his data, in order to exercise what he believes are his data subject rights. What is the time period in which Mike should receive a response to his request?
-
A
Not more than one month of receipt of Mike's request.
-
B
Not more than two months after verifying Mike's identity.
-
C
When all the information about Mike has been collected.
-
D
Not more than thirty days after submission of Mike's request.
Reveal answer details
Close answer details
If a company is planning to use closed-circuit television (CCTV) on its premises and is concerned with GDPR compliance, it should first do all of the following EXCEPT?
-
A
Notify the appropriate data protection authority.
-
B
Perform a data protection impact assessment (DPIA).
-
C
Create an information retention policy for those who operate the system.
-
D
Ensure that safeguards are in place to prevent unauthorized access to the footage.
Reveal answer details
Close answer details
A multinational company is appointing a mandatory data protection officer. In addition to considering the rules set out in Article 37 (1) of the GDPR, which of the following actions must the company also undertake to ensure compliance in all EU jurisdictions in which it operates?
-
A
Consult national derogations to evaluate if there are additional cases to be considered in relation to the matter.
-
B
Conduct a Data Protection Privacy Assessment on the processing operations of the company in all the countries it operates.
-
C
Assess whether the company has more than 250 employees in each of the EU member-states in which it is established.
-
D
Revise the data processing activities of the company that affect more than one jurisdiction to evaluate whether they comply with the principles of privacy by design and by default.
Reveal answer details
Close answer details
SCENARIO Please use the following to answer the next question: The fitness company Vigotron has recently developed a new app called M-Health, which it wants to market on its website as a free download. Vigotron's marketing manager asks his assistant Emily to create a webpage that describes the app and specifies the terms of use. Emily, who is new at Vigotron, is excited about this task. At her previous job she took a data protection class, and though the details are a little hazy, she recognizes that Vigotron is going to need to obtain user consent for use of the app in some cases. Emily sketches out the following draft, trying to cover as much as possible before sending it to Vigotron's legal department. Registration Form Vigotron's new M-Health app makes it easy for you to monitor a variety of health-related activities, including diet, exercise, and sleep patterns. M-Health relies on your smartphone settings (along with other third-party apps you may already have) to collect data about all of these important lifestyle elements, and provide the information necessary for you to enrich your quality of life. (Please click here to read a full description of the services that M-Health provides.) Vigotron values your privacy. The M-Heaith app allows you to decide which information is stored in it, and which apps can access your data. When your device is locked with a passcode, all of your health and fitness data is encrypted with your passcode. You can back up data stored in the Health app to Vigotron's cloud provider, Stratculous. (Read more about Stratculous here.) Vigotron will never trade, rent or sell personal information gathered from the M-Health app. Furthermore, we will not provide a customer's name, email address or any other information gathered from the app to any third-party without a customer's consent, unless ordered by a court, directed by a subpoena, or to enforce the manufacturer's legal rights or protect its business or property. We are happy to offer the M-Health app free of charge. If you want to download and use it, we ask that you first complete this registration form. (Please note that use of the M-Health app is restricted to adults aged 16 or older, unless parental consent has been given to minors intending to use it.) First name: Surname: Year of birth: Email: Physical Address (optional*): Health status: *If you are interested in receiving newsletters about our products and services that we think may be of interest to you, please include your physical address. If you decide later that you do not wish to receive these newsletters, you can unsubscribe by sending an email to [email protected] or send a letter with your request to the address listed at the bottom of this page. Terms and Conditions 1. Jurisdiction. [...] 2. Applicable law. [...] 3. Limitation of liability. [...] Consent By completing this registration form, you attest that you are at least 16 years of age, and that you consent to the processing of your personal data by Vigotron for the purpose of using the M-Health app. Although you are entitled to opt out of any advertising or marketing, you agree that Vigotron may contact you or provide you with any required notices, agreements, or other information concerning the services by email or other electronic means. You also agree that the Company may send automated emails with alerts regarding any problems with the M-Health app that may affect your well being. If a user of the M-Health app were to decide to withdraw his consent, Vigotron would first be required to do what?
-
A
Provide the user with logs of data collected through use of the app.
-
B
Erase any data collected from the time the app was first used.
-
C
Inform any third parties of the user's withdrawal of consent.
-
D
Cease processing any data collected through use of the app.
Reveal answer details
Close answer details
A company in France suffers a robbery over the weekend owing to a faulty alarm system. When it is determined that the break-in involves the loss of a substantial amount of data, the company decides on a CCTV system to monitor for future incidents. Company technicians install cameras in the entrance of the building, hallways and offices. Footage is recorded continuously, and is monitored by the home office in the United States. What is the most realistic step the company could take to address their security concerns and comply with the personal data processing principles set out in Article 5 of the GDPR?
-
A
Seek informed consent from company employees.
-
B
Have cameras recording during work hours only.
-
C
Retain captured footage for no more than 30 days.
-
D
Restrict camera placement to building entrances only.
Reveal answer details
Close answer details
Under the GDPR, where personal data is not obtained directly from the data subject, a controller is exempt from directly providing information about processing to the data subject if?
-
A
The data subject already has information regarding how his data will be used
-
B
The provision of such information to the data subject would be too problematic
-
C
Third-party data would be disclosed by providing such information to the data subject
-
D
The processing of the data subject's data is protected by appropriate technical measures
Reveal answer details
Close answer details
Correct answerA
ExplanationReferences: https://dataprivacymanager.net/gdpr-exemptions-from-the-obligation-to-provide-information-to-the-individual-data-subject/
Why is advisable to avoid consent as a legal basis for an employer to process employee data?
-
A
Employee data can only be processed if there is an approval from the data protection officer.
-
B
Consent may not be valid if the employee feels compelled to provide it.
-
C
An employer might have difficulty obtaining consent from every employee.
-
D
Data protection laws do not apply to processing of employee data.
Reveal answer details
Close answer details
Which mechanism, introduced by the GDPR as a means of ensuring both compliance and transparency, allows for the possibility of personal data transfers to third countries under Article 42?
-
A
-
B
-
C
Law enforcement requests.
-
D
Standard contractual clauses.
Reveal answer details
Close answer details
ISO 31700 has set forth requirements relating to consumer products and services. In particular, this international standard focuses on the implementation of which of the following?
-
A
-
B
Comprehensive ethical AI software.
-
C
Privacy notices for companies providing services to consumers.
-
D
Automated systems for identifying EU data subjects' personal data.
Reveal answer details
Close answer details
Question 10
Single choice
SCENARIO - Please use the following to answer the next question: Gentle Hedgehog Inc. is a privately owned website design agency incorporated in Italy. The company has numerous remote workers in different EU countries. Recently, the management of Gentle Hedgehog noticed a decrease in productivity of their sales team, especially among remote workers. As a result, the company plans to implement a robust but privacy-friendly remote surveillance system to prevent absenteeism, reward top performers, and ensure the best quality of customer service when sales people are interacting with customers. Gentle Hedgehog eventually hires Sauron Eye Inc., a Chinese vendor of employee surveillance software whose European headquarters is in Germany. Sauron Eye s software provides powerful remote-monitoring capabilities, including 24/7 access to computer cameras and microphones, screen captures, emails, website history, and keystrokes. Any device can be remotely monitored from a central server that is securely installed at Gentle Hedgehog headquarters. The monitoring is invisible by default; however, a so-called Transparent Mode, which regularly and conspicuously notifies all users about the monitoring and its precise scope, also exists. Additionally, the monitored employees are required to use a built-in verification technology involving facial recognition each time they log in. All monitoring data, including the facial recognition data, is securely stored in Microsoft Azure cloud servers operated by Sauron Eye, which are physically located in France. Based on the scenario, what are the primary privacy risks of the planned surveillance system?
-
A
A Chinese vendor and the monitoring of EU-based employees.
-
B
Facial recognition data stored in the cloud and lack of encryption.
-
C
Excessive scope of monitoring and lack of legitimate purpose for data collection.
-
D
Missing E2EE encryption in the monitoring system and unclear data storage duration.
Reveal answer details
Close answer details
Question 11
Single choice
In the Planet 49 case, what was the man judgement of the Coon of Justice of the European Union (CJEU) regarding the issue of cookies?
-
A
If the cookies do not track personal data, then pre-checked boxes are acceptable.
-
B
If the ePrivacy Directive requires consent for cookies, then the GDPR's consent requirements apply.
-
C
If a website's cookie notice makes clear the information gathered and the lifespan of the cookie, then pre-checked boxes are acceptable.
-
D
If a data subject continues to scroll through a website after reading a cookie banner, this activity constitutes valid consent for the tracking described in the cookie banner.
Reveal answer details
Close answer details
Question 12
Single choice
The origin of privacy as a fundamental human right can be found in which document?
-
A
Universal Declaration of Human Rights 1948.
-
B
European Convention of Human Rights 1953.
-
C
OECD Guidelines on the Protection of Privacy 1980.
-
D
Charier of Fundamental Rights of the European Union 2000.
Reveal answer details
Close answer details
Question 13
Single choice
According to Art 23 GDPR, which of the following data subject rights can NOT be restricted?
-
A
Right to restriction of processing.
-
B
Right to erasure ("Right to be forgotten").
-
C
Right to lodge a complaint with a supervisory authority.
-
D
Right not to be subject to automated individual decision-making
Reveal answer details
Close answer details
Question 14
Single choice
SCENARIO Please use the following to answer the next question: Liem, an online retailer known for its environmentally friendly shoes, has recently expanded its presence in Europe. Anxious to achieve market dominance, Liem teamed up with another eco friendly company, EcoMick, which sells accessories like belts and bags. Together the companies drew up a series of marketing campaigns designed to highlight the environmental and economic benefits of their products. After months of planning, Liem and EcoMick entered into a data sharing agreement to use the same marketing database, MarketIQ, to send the campaigns to their respective contacts. Liem and EcoMick also entered into a data processing agreement with MarketIQ, the terms of which included processing personal data only upon Liem and EcoMick's instructions, and making available to them all information necessary to demonstrate compliance with GDPR obligations. Liem and EcoMick then procured the services of a company called JaphSoft, a marketing optimization firm that uses machine learning to help companies run successful campaigns. Clients provide JaphSoft with the personal data of individuals they would like to be targeted in each campaign. To ensure protection of its clients' data, JaphSoft implements the technical and organizational measures it deems appropriate. JaphSoft works to continually improve its machine learning models by analyzing the data it receives from its clients to determine the most successful components of a successful campaign. JaphSoft then uses such models in providing services to its client-base. Since the models improve only over a period of time as more information is collected, JaphSoft does not have a deletion process for the data it receives from clients. However, to ensure compliance with data privacy rules, JaphSoft pseudonymizes the personal data by removing identifying information from the contact information. JaphSoft's engineers, however, maintain all contact information in the same database as the identifying information. Under its agreement with Liem and EcoMick, JaphSoft received access to MarketIQ, which included contact information as well as prior purchase history for such contacts, to create campaigns that would result in the most views of the two companies' websites. A prior Liem customer, Ms. Iman, received a marketing campaign from JaphSoft regarding Liem's as well as EcoMick's latest products. While Ms. Iman recalls checking a box to receive information in the future regarding Liem's products, she has never shopped EcoMick, nor provided her personal data to that company. For what reason would JaphSoft be considered a controller under the GDPR?
-
A
It determines how long to retain the personal data collected.
-
B
It has been provided access to personal data in the MarketIQ database.
-
C
It uses personal data to improve its products and services for its client-base through machine learning.
-
D
It makes decisions regarding the technical and organizational measures necessary to protect the personal data.
Reveal answer details
Close answer details
Question 15
Single choice
Under which of the following conditions does the General Data Protection Regulation NOT apply to the processing of personal data?
-
A
When the personal data is processed only in non-electronic form
-
B
When the personal data is collected and then pseudonymised by the controller
-
C
When the personal data is held by the controller but not processed for further purposes
-
D
When the personal data is processed by an individual only for their household activities
Reveal answer details
Close answer details
Question 16
Single choice
A high-ranking employee has his laptop bag stolen in a train station. In addition to the laptop, the bag contained the employee's ID card, confidential company documents (such as financial information and minutes of board meetings, including participants and their roles), company payment cards, and authorization tokens. As the company's Data Protection Officer, what should be your first action?
-
A
Inform the appropriate supervisory authority of the breach.
-
B
Verify whether the laptop contained personal data and, if so, if it was encrypted.
-
C
Inform the meeting participants of the breach and provide them with next steps to be taken.
-
D
Request deactivation of the authorization tokens to avoid access to company data, and remotely wipe the laptop.
Reveal answer details
Close answer details
Question 17
Single choice
Article 9 of the GDPR lists exceptions to the general prohibition against processing biometric data. Which of the following is NOT one of these exceptions?
-
A
The processing is done by a non-profit organization and the results are disclosed outside the organization.
-
B
The processing is necessary to protect the vital interests of the data subject when he or she is incapable of giving consent.
-
C
The processing is necessary for the establishment, exercise or defense of legal claims when courts are acting in a judicial capacity.
-
D
The processing is explicitly consented to by the data subject and he or she is allowed by Union or Member State law to lift the prohibition.
Reveal answer details
Close answer details
Correct answerA
ExplanationReferences: https://dataprivacymanager.net/sensitive-personal-data-special-category-under-the-gdpr/
Question 18
Single choice
SCENARIO Please use the following to answer the next question: Joe is the new privacy manager for Who-R-U, a Canadian business that provides DNA analysis. The company is headquartered in Montreal, and all of its employees arelocated there. The company offers its services to Canadians only: Its website is in English and French, it accepts only Canadian currency, and it blocks internet traffic from outside of Canada (although this solution doesn't prevent all non-Canadian traffic). It also declines to process orders that request the DNA report to be sent outside of Canada, and returns orders that show a non-Canadian return address. Bob, the President of Who-R-U, thinks there is a lot of interest for the product in the EU, and the company is exploring a number of plans to expand its customer base. The first plan, collegially called We-Track-U, will use an app to collect information about its current Canadian customer base. The expansion will allow its Canadian customers to use the app while traveling abroad. He suggests that the company use this app to gather location information. If the plan shows promise, Bob proposes to use push notifications and text messages to encourage existing customers to pre-register for an EU version of the service. Bob calls this work plan, We-Text-U. Once the company has gathered enough pre-registrations, it will develop EU-specific content and services. Another plan is called Customer for Life. The idea is to offer additional services through the company's app, like storage and sharing of DNA information with other applications and medical providers. The company's contract says that it can keep customer DNA indefinitely, and use it to offer new services and market them to customers. It also says that customers agree not to withdraw direct marketing consent. Paul, the marketing director, suggests that the company should fully exploit these provisions, and that it can work around customers' attempts to withdraw consent because the contract invalidates them. The final plan is to develop a brand presence in the EU. The company has already begun this process. It is in the process of purchasing the naming rights for a building in Germany, which would come with a few offices that Who-R-U executives can use while traveling internationally. The office doesn't include any technology or infrastructure; rather, it's simply a room with a desk and some chairs. On a recent trip concerning the naming-rights deal, Bob's laptop is stolen. The laptop held unencrypted DNA reports on 5,000 Who-R-U customers, all of whom are residents of Canada. The reports include customer name, birthdate, ethnicity, racial background, names of relatives, gender, and occasionally health information. Who-R-U is NOT required to notify the local German DPA about the laptop theft because?
-
A
The company isn't a controller established in the Union.
-
B
The laptop belonged to a company located in Canada.
-
C
The data isn't considered personally identifiable financial information.
-
D
There is no evidence that the thieves have accessed the data on the laptop.
Reveal answer details
Close answer details
Question 19
Single choice
Which of the following would MOST likely trigger the extraterritorial effect of the GDPR, as specified by Article 3?
-
A
The behavior of suspected terrorists being monitored by EU law enforcement bodies.
-
B
Personal data of EU citizens being processed by a controller or processor based outside the EU.
-
C
The behavior of EU citizens outside the EU being monitored by non-EU law enforcement bodies.
-
D
Personal data of EU residents being processed by a non-EU business that targets EU customers.
Reveal answer details
Close answer details
Correct answerD
ExplanationReferences: https://hsfnotes.com/data/2019/12/02/edpb-adopts-final-guidelines-on-gdpr-extra-territoriality/
Question 20
Single choice
Which aspect of processing does the GDPR allow processors to determine for themselves?
-
A
The question of whether the controller needs to be informed about the substitution of another processor carrying out specific processing activities on behalf of the controller.
-
B
Their own purposes for the processing, if such purposes are compatible with those for which the personal data were initially collected.
-
C
The parameters of their marketing campaigns using personal data relating to the controller's customers.
-
D
Their own type of hardware or software and the specific security measures for the processing.
Reveal answer details
Close answer details
Question 21
Single choice
In 2016's Guidance, the United Kingdom's Information Commissioner's Office (ICO) reaffirmed the importance of using a "layered notice" to provide data subjects with what?
-
A
A privacy notice containing brief information whilst offering access to further detail.
-
B
A privacy notice explaining the consequences for opting out of the use of cookies on a website.
-
C
An explanation of the security measures used when personal data is transferred to a third party.
-
D
An efficient means of providing written consent in member states where they are required to do so.
Reveal answer details
Close answer details
Question 22
Single choice
Which area of privacy is a lead supervisory authority's (LSA) MAIN concern?
-
A
-
B
-
C
-
D
Special categories of data
Reveal answer details
Close answer details
Correct answerC
ExplanationReferences: https://iapp.org/news/a/is-it-possible-to-choose-your-lead-supervisory-authority-under-the-gdpr/
Question 23
Single choice
Following the United Kingdom's withdrawal from the European Union, what law do companies established in the UK and processing the personal data of people in the EU need to adhere to?
-
A
The Privacy and Electronic Communications Regulations.
-
B
The EU General Data Protection Regulation.
-
C
The UK General Data Protection Regulation.
-
D
The UK Data Protection Act.
Reveal answer details
Close answer details
Question 24
Single choice
In which situation would a data controller most likely be able to justify the processing of the data of a child without parental consent?
-
A
When the data is to be processed for market research.
-
B
When providing preventive or counselling services to the child.
-
C
When providing the child with materials purely for educational use.
-
D
When a legitimate business interest makes obtaining consent impractical.
Reveal answer details
Close answer details
Question 25
Single choice
SCENARIO Please use the following to answer the next question: Liem, an online retailer known for its environmentally friendly shoes, has recently expanded its presence in Europe. Anxious to achieve market dominance, Liem teamed up with another eco friendly company, EcoMick, which sells accessories like belts and bags. Together the companies drew up a series of marketing campaigns designed to highlight the environmental and economic benefits of their products. After months of planning, Liem and EcoMick entered into a data sharing agreement to use the same marketing database, MarketIQ, to send the campaigns to their respective contacts. Liem and EcoMick also entered into a data processing agreement with MarketIQ, the terms of which included processing personal data only upon Liem and EcoMick's instructions, and making available to them all information necessary to demonstrate compliance with GDPR obligations. Liem and EcoMick then procured the services of a company called JaphSoft, a marketing optimization firm that uses machine learning to help companies run successful campaigns. Clients provide JaphSoft with the personal data of individuals they would like to be targeted in each campaign. To ensure protection of its clients' data, JaphSoft implements the technical and organizational measures it deems appropriate. JaphSoft works to continually improve its machine learning models by analyzing the data it receives from its clients to determine the most successful components of a successful campaign. JaphSoft then uses such models in providing services to its client-base. Since the models improve only over a period of time as more information is collected, JaphSoft does not have a deletion process for the data it receives from clients. However, to ensure compliance with data privacy rules, JaphSoft pseudonymizes the personal data by removing identifying information from the contact information. JaphSoft's engineers, however, maintain all contact information in the same database as the identifying information. Under its agreement with Liem and EcoMick, JaphSoft received access to MarketIQ, which included contact information as well as prior purchase history for such contacts, to create campaigns that would result in the most views of the two companies' websites. A prior Liem customer, Ms. Iman, received a marketing campaign from JaphSoft regarding Liem's as well as EcoMick's latest products. While Ms. Iman recalls checking a box to receive information in the future regarding Liem's products, she has never shopped EcoMick, nor provided her personal data to that company. Which of the following BEST describes the relationship between Liem, EcoMick and JaphSoft?
-
A
Liem is a controller and EcoMick is a processor because Liem provides specific instructions regarding how the marketing campaigns should be rolled out.
-
B
EcoMick and JaphSoft are is a controller and Liem is a processor because EcoMick is sharing its marketing data with Liem for contacts in Europe.
-
C
JaphSoft is the sole processor because it processes personal data on behalf of its clients.
-
D
Liem and EcoMick are joint controllers because they carry out joint marketing activities.
Reveal answer details
Close answer details
Question 26
Single choice
SCENARIO Please use the following to answer the next question: Jane starts her new role as a Data Protection Officer (DPO) at a Malta-based company that allows anyone to buy and sell cryptocurrencies via its online platform. The company stores and processes the personal data of its customers in a dedicated data center located in Malta (EU). People wishing to trade cryptocurrencies are required to open an online account on the platform. They then must successfully pass a Know Your Customer (KYC) due diligence procedure aimed at preventing money laundering and ensuring compliance with applicable financial regulations. The non-European customers are also required to waive all their GDPR rights by reading a disclaimer written in bold and ticking a checkbox on a separate page in order to get their account approved on the platform. All customers must likewise accept the terms of service of the platform. The terms of service also include a privacy policy section, saying, among other things, that if a customer fails the KYC process, its KYC data will be automatically shared with the national anti-money laundering agency. The KYC procedure requires customers to answer many questions, including whether they have any criminal convictions, whether they use recreational drugs or have problems with alcohol, and whether they have a terminal illness. While providing this data, customers see a conspicuous message saying that this data is meant only to prevent fraud and account takeover, and will be never shared with private third parties. The company regularly conducts external security testing of its online systems by independent cybersecurity companies from the EU. At the final stage of testing, the company provides cybersecurity assessors with access to its central database to review security permissions, roles and policies. Personal data in the database is encrypted; however, cybersecurity assessors usually have access to the decryption keys obtained while running initial security testing. The assessors must strictly follow the guidelines imposed by the company during the entire testing and auditing process. All customer data, including trading activities and all internal communications with technical support, are permanently stored in a secured AWS S3 Glacier cloud data storage, located in Ireland, for backup and compliance purposes. The data is securely transferred to the cloud and then is properly encrypted while at rest by using AWS-native encryption mechanisms. These mechanisms give AWS the necessary technical means to encrypt and decrypt the data when such is required by the company. There is no data processing agreement between AWS and the company. Which of the following must be a component of the anti-money-laundering data-sharing practice of the platform?
-
A
The terms of service shall also enumerate all applicable anti-money laundering few.
-
B
Customers shall have an opt-out feature to restrict data sharing with law enforcement agencies after the registration.
-
C
The terms of service shall include the address of the anti-money laundering agency and contacts of the investigators who may access me data.
-
D
Customers snail receive a clear and conspicuous notice about such data sharing before submitting their data during the registration process.
Reveal answer details
Close answer details
Question 27
Single choice
To provide evidence of GDPR compliance, a company performs an internal audit. As a result, it finds a data base, password-protected, listing all the social network followers of the client. Regarding the domain of the controller-processor relationships, how is this situation considered?
-
A
Compliant with the security principle, because the data base is password-protected.
-
B
Non-compliant, because the storage of the data exceeds the tasks contractually authorized by the controller.
-
C
Not applicable, because the data base is password protected, and therefore is not at risk of identifying any data subject.
-
D
Compliant with the storage limitation principle, so long as the internal auditor permanently deletes the data base.
Reveal answer details
Close answer details
Question 28
Single choice
SCENARIO Please use the following to answer the next question: Due to rapidly expanding workforce, Company A has decided to outsource its payroll function to Company B. Company B is an established payroll service provider with a sizable client base and a solid reputation in the industry. Company B's payroll solution for Company A relies on the collection of time and attendance data obtained via a biometric entry system installed in each of Company A's factories. Company B won't hold any biometric data itself, but the related data will be uploaded to Company B's UK servers and used to provide the payroll service. Company B's live systems will contain the following information for each of Company A's employees: Name Address Date of Birth Payroll number National Insurance number Sick pay entitlement Maternity/paternity pay entitlement Holiday entitlement Pension and benefits contributions Trade union contributions Jenny is the compliance officer at Company A. She first considers whether Company A needs to carry out a data protection impact assessment in relation to the new time and attendance system, but isn't sure whether or not this is required. Jenny does know, however, that under the GDPR there must be a formal written agreement requiring Company B to use the time and attendance data only for the purpose of providing the payroll service, and to apply appropriate technical and organizational security measures for safeguarding the data. Jenny suggests that Company B obtain advice from its data protection officer. The company doesn't have a DPO but agrees, in the interest of finalizing the contract, to sign up for the provisions in full. Company A enters into the contract. Weeks later, while still under contract with Company A, Company B embarks upon a separate project meant to enhance the functionality of its payroll service, and engages Company C to help. Company C agrees to extract all personal data from Company B's live systems in order to create a new database for Company B. This database will be stored in a test environment hosted on Company C's U.S. server. The two companies agree not to include any data processing provisions in their services agreement, as data is only being used for IT testing purposes. Unfortunately, Company C's U.S. server is only protected by an outdated IT security system, and suffers a cyber security incident soon after Company C begins work on the project. As a result, data relating to Company A's employees is visible to anyone visiting Company C's website. Company A is unaware of this until Jenny receives a letter from the supervisory authority in connection with the investigation that ensues. As soon as Jenny is made aware of the breach, she notifies all affected employees. Under the GDPR, which of Company B's actions would NOT be likely to trigger a potential enforcement action?
-
A
Their omission of data protection provisions in their contract with Company C.
-
B
Their failure to provide sufficient security safeguards to Company A's data.
-
C
Their engagement of Company C to improve their payroll service.
-
D
Their decision to operate without a data protection officer.
Reveal answer details
Close answer details
Question 29
Single choice
Under Article 21 of the GDPR, a controller must stop profiling when requested by a data subject, unless it can demonstrate compelling legitimate grounds that override the interests of the individual. In the Guidelines on Automated individual decision-making and Profiling, the WP 29 says the controller needs to do all of the following to demonstrate that it has such legitimate grounds EXCEPT?
-
A
Carry out an exercise that weighs the interests of the controller and the basis for the data subject's objection.
-
B
Consider the impact of the profiling on the data subject's interest, rights and freedoms.
-
C
Demonstrate that the profiling is for the purposes of direct marketing.
-
D
Consider the importance of the profiling to their particular objective.
Reveal answer details
Close answer details
Correct answerC
ExplanationReferences: https://gdpr-info.eu/art-21-gdpr/
Question 30
Single choice
In which case would a controller who has undertaken a DPIA most likely need to consult with a supervisory authority?
-
A
Where the DPIA identifies that personal data needs to be transferred to other countries outside of the EEA.
-
B
Where the DPIA identifies high risks to individuals' rights and freedoms that the controller can take steps to reduce.
-
C
Where the DPIA identifies that the processing being proposed collects the sensitive data of EU citizens.
-
D
Where the DPIA identifies risks that will require insurance for protecting its business interests.
Reveal answer details
Close answer details
Correct answerB
ExplanationReferences: https://www.dataguidance.com/opinion/eu-how-when-and-why-carrying-out-dpia
Question 31
Single choice
The transparency principle is most directly related to which of the following rights?
-
A
-
B
-
C
-
D
Right to restriction of processing.
Reveal answer details
Close answer details
Question 32
Single choice
A company has collected personal data tor direct marketing purpose on the basis of consent. It is now considering using this data to develop new products through analytics. What is the company first required to do?
-
A
Obtain specific consent for the new processing
-
B
Only inform the data subjects of the new purpose.
-
C
Proceed no further, as such repurposing is unlawful
-
D
Update the privacy notice upon which consent was given
Reveal answer details
Close answer details
Question 33
Single choice
In the EDPB's Guidelines 4/2019 on Article 25 Data Protection by Design and by Default, all of the following practices follow from the principles relating to the processing of personal data under EU data protection law EXCEPT?
-
A
Data ownership allocation.
-
B
Access control management.
-
C
Frequent pseudonymization key rotation.
-
D
Error propagation avoidance along the processing chain.
Reveal answer details
Close answer details
Question 34
Single choice
After leaving the EU under the terms of Brexit, the United Kingdom will seek an adequacy determination. What is the reason for this?
-
A
The Insurance Commissioner determined that an adequacy determination is required by the Data Protection Act.
-
B
Adequacy determinations automatically lapse when a Member State leaves the EU.
-
C
The UK is now a third country because it's no longer subject to the GDPR.
-
D
The UK is less trustworthy now that its not part of the Union.
Reveal answer details
Close answer details
Correct answerC
ExplanationReferences: https://www.euractiv.com/section/digital/news/commission-must-refuse-uk-data-adequacy-rights-group-says/
Question 35
Single choice
SCENARIO Please use the following to answer the next question: Brady is a computer programmer based in New Zealand who has been running his own business for two years. Brady's business provides a low-cost suite of services to customers throughout the European Economic Area (EEA). The services are targeted towards new and aspiring small business owners. Brady's company, called Brady Box, provides web page design services, a Social Networking Service (SNS) and consulting services that help people manage their own online stores. Unfortunately, Brady has been receiving some complaints. A customer named Anna recently uploaded her plans for a new product onto Brady Box's chat area, which is open to public viewing. Although she realized her mistake two weeks later and removed the document, Anna is holding Brady Box responsible for not noticing the error through regular monitoring of the website. Brady believes he should not be held liable. Another customer, Felipe, was alarmed to discover that his personal information was transferred to a third-party contractor called Hermes Designs and worries that sensitive information regarding his business plans may be misused. Brady does not believe he violated European privacy rules. He provides a privacy notice to all of his customers explicitly stating that personal data may be transferred to specific third parties in fulfillment of a requested service. Felipe says he read the privacy notice but that it was long and complicated Brady continues to insist that Felipe has no need to be concerned, as he can personally vouch for the integrity of Hermes Designs. In fact, Hermes Designs has taken the initiative to create sample customized banner advertisements for customers like Felipe. Brady is happy to provide a link to the example banner ads, now posted on the Hermes Designs webpage. Hermes Designs plans on following up with direct marketing to these customers. Brady was surprised when another customer, Serge, expressed his dismay that a quotation by him is being used within a graphic collage on Brady Box's home webpage. The quotation is attributed to Serge by first and last name. Brady, however, was not worried about any sort of litigation. He wrote back to Serge to let him know that he found the quotation within Brady Box's Social Networking Service (SNS), as Serge himself had posted the quotation. In his response, Brady did offer to remove the quotation as a courtesy. Despite some customer complaints, Brady's business is flourishing. He even supplements his income through online behavioral advertising (OBA) via a third-party ad network with whom he has set clearly defined roles. Brady is pleased that, although some customers are not explicitly aware of the OBA, the advertisements contain useful products and services. Based on the scenario, what is the main reason that Brady should be concerned with Hermes Designs' handling of customer personal data?
-
A
-
B
The data is uncategorized.
-
C
The data is being used for a new purpose.
-
D
The data is being processed via a new means.
Reveal answer details
Close answer details
Question 36
Single choice
SCENARIO Please use the following to answer the next question: Louis, a long-time customer of Bedrock Insurance, was involved in a minor car accident a few months ago. Although no one was hurt, Louis has been plagued by texts and calls from a company called Accidentable offering to help him recover compensation for personal injury. Louis has heard about insurance companies selling customers' data to third parties, and he's convinced that Accidentable must have gotten his information from Bedrock Insurance. Louis has also been receiving an increased amount of marketing information from Bedrock, trying to sell him their full range of their insurance policies. Perturbed by this, Louis has started looking at price comparison sites on the internet and has been shocked to find that other insurers offer much cheaper rates than Bedrock, even though he has been a loyal customer for many years. When his Bedrock policy comes up for renewal, he decides to switch to Zantrum Insurance. In order to activate his new insurance policy, Louis needs to supply Zantrum with information about his No Claims bonus, his vehicle and his driving history. After researching his rights under the GDPR, he writes to ask Bedrock to transfer his information directly to Zantrum. He also takes this opportunity to ask Bedrock to stop using his personal data for marketing purposes. Bedrock supplies Louis with a PDF and XML (Extensible Markup Language) versions of his No Claims Certificate, but tells Louis it cannot transfer his data directly to Zantrum as this is not technically feasible. Bedrock also explains that Louis's contract included a provision whereby Louis agreed that his data could be used for marketing purposes; according to Bedrock, it is too late for Louis to change his mind about this. It angers Louis when he recalls the wording of the contract, which was filled with legal jargon and very confusing. In the meantime, Louis is still receiving unwanted calls from Accidentable Insurance. He writes to Accidentable to ask for the name of the organization that supplied his details to them. He warns Accidentable that he plans to complain to the data protection authority, because he thinks their company has been using his data unlawfully. His letter states that he does not want his data being used by them in any way. Accidentable's response letter confirms Louis's suspicions. Accidentable is Bedrock Insurance's wholly owned subsidiary, and they received information about Louis's accident from Bedrock shortly after Louis submitted his accident claim. Accidentable assures Louis that there has been no breach of the GDPR, as Louis's contract included, a provision in which he agreed to share his information with Bedrock's affiliates for business purposes. Louis is disgusted by the way in which he has been treated by Bedrock, and writes to them insisting that all his information be erased from their computer system. After Louis has exercised his right to restrict the use of his data, under what conditions would Accidentable have grounds for refusing to comply?
-
A
If Accidentable is entitled to use of the data as an affiliate of Bedrock.
-
B
If Accidentable also uses the data to conduct public health research.
-
C
If the data becomes necessary to defend Accidentable's legal rights.
-
D
If the accuracy of the data is not an aspect that Louis is disputing.
Reveal answer details
Close answer details
Question 37
Single choice
In addition to the European Commission, who can adopt standard contractual clauses, assuming that all required conditions are met?
-
A
Approved data controllers.
-
B
The Council of the European Union.
-
C
National data protection authorities.
-
D
The European Data Protection Supervisor.
Reveal answer details
Close answer details
Correct answerC
ExplanationReferences: https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection/ standard-contractual-clauses-scc_en
Question 38
Single choice
SCENARIO Please use the following to answer the next question: ProStorage is a multinational cloud storage provider headquartered in the Netherlands. Its CEO, Ruth Brown, has developed a two-pronged strategy for growth: 1) expand ProStorage's global customer base and 2) increase ProStorage's sales force by efficiently onboarding effective teams. Enacting this strategy has recently been complicated by Ruth's health condition, which has limited her working hours, as well as her ability to travel to meet potential customers. ProStorage's Human Resources department and Ruth's Chief of Staff now work together to manage her schedule and ensure that she is able to make all her medical appointments. The latter has become especially crucial after Ruth's last trip to India, where she suffered a medical emergency and was hospitalized in New Delhi. Unable to reach Ruth's family, the hospital reached out to ProStorage and was able to connect with her Chief of Staff, who in coordination with Mary, the head of HR, provided information to the doctors based on accommodation requests Ruth made when she started at ProStorage. In support of Ruth's strategic goals of hiring more sales representatives, the Human Resources team is focused on improving its processes to ensure that new employees are sourced, interviewed, hired, and on boarded efficiently. To help with this, Mary identified two vendors, HRYourWay, a German based company, and InstaHR, an Australian based company. She decided to have both vendors go through ProStorage's vendor risk review process so she can work with Ruth to make the final decision. As part of the review process, Jackie, who is responsible for maintaining ProStorage's privacy program (including maintaining controller BCRs and conducting vendor risk assessments), reviewed both vendors but completed a transfer impact assessment only for InstaHR. After her review of both vendors, she determined that InstaHR satisfied more of the requirements as it boasted a more established privacy program and provided third-party attestations, whereas HRYourWay was a small vendor with minimal data protection operations. Thus, she recommended InstaHR. ProStorage's marketing team also worked to meet the strategic goals of the company by focusing on industries where it needed to grow its market share. To help with this, the team selected as a partner UpFinance. a US based company with deep connections to financial industry customers. During ProStorage's diligence process, Jackie from the privacy team noted in the transfer impact assessment that UpFinance implements several data protection measures including end-lo-end encryption, with encryption keys held by the customer. Notably, UpFinance has not received any government requests in its 7 years of business. Still, Jackie recommended that the contract require UpFinance to notify ProStorage if it receives a government request for personal data UpFinance processes on its behalf prior to disclosing such data. Why was Jackie correct in not completing a transfer impact assessment for HRYourWay?
-
A
HRYourWay was ultimately not selected
-
B
HRYourWay is not located in a third country.
-
C
ProStorage will obtain consent for all transfers.
-
D
ProStorage can rely on its Binding Corporate Rules
Reveal answer details
Close answer details
Question 39
Single choice
Which of the following is NOT exempt from the material scope of the GDPR. insofar as the processing of personal data is concerned?
-
A
A natural person in the course of a large-scale but purely personal or household activity.
-
B
A natural person processing data foe a small-scale, purely personal or household activity.
-
C
A natural person in the course of processing purely personal or household data on behalf of a spouse who is beyond the age of majority.
-
D
A natural person in the course of activity conducted purely tor a personally-owned sole proprietorship.
Reveal answer details
Close answer details
Question 40
Single choice
If a multi-national company wanted to conduct background checks on all current and potential employees, including those based in Europe, what key provision would the company have to follow?
-
A
Background checks on employees could be performed only under prior notice to all employees.
-
B
Background checks are only authorized with prior notice and express consent from all employees including those based in Europe.
-
C
Background checks on European employees will stem from data protection and employment law, which can vary between member states.
-
D
Background checks may not be allowed on European employees, but the company can create lists based on its legitimate interests, identifying individuals who are ineligible for employment.
Reveal answer details
Close answer details
Correct answerC
ExplanationReferences: https://www.shrm.org/resourcesandtools/tools-and-samples/toolkits/pages/ conductingbackgroundinvestigations.aspx
Question 41
Single choice
Article 58 of the GDPR describes the power of supervisory authorities. Which of the following is NOT among those granted?
-
A
-
B
-
C
-
D
Authorization and advisory powers.
Reveal answer details
Close answer details
Correct answerA
ExplanationReferences: https://www.privacy-regulation.eu/en/article-58-powers-GDPR.htm
Question 42
Single choice
What is the most frequently used mechanism for legitimizing cross-border data transfer?
-
A
Standard Contractual Clauses.
-
B
Approved Code of Conduct.
-
C
-
D
Reveal answer details
Close answer details
Correct answerA
ExplanationReferences: https://www.dataguidance.com/opinion/international-eu-us-cross-border-data-transfers
Question 43
Single choice
The European Parliament jointly exercises legislative and budgetary functions with which of the following?
-
A
-
B
The Article 29 Working Party.
-
C
The Council of the European Union.
-
D
The European Data Protection Board.
Reveal answer details
Close answer details
Question 44
Single choice
SCENARIO Please use the following to answer the next question: Joe is the new privacy manager for Who-R-U, a Canadian business that provides DNA analysis. The company is headquartered in Montreal, and all of its employees are located there. The company offers its services to Canadians only: Its website is in English and French, it accepts only Canadian currency, and it blocks internet traffic from outside of Canada (although this solution doesn't prevent all non-Canadian traffic). It also declines to process orders that request the DNA report to be sent outside of Canada, and returns orders that show a non-Canadian return address. Bob, the President of Who-R-U, thinks there is a lot of interest for the product in the EU, and the company is exploring a number of plans to expand its customer base. The first plan, collegially called We-Track-U, will use an app to collect information about its current Canadian customer base. The expansion will allow its Canadian customers to use the app while traveling abroad. He suggests that the company use this app to gather location information. If the plan shows promise, Bob proposes to use push notifications and text messages to encourage existing customers to pre-register for an EU version of the service. Bob calls this work plan, We-Text-U. Once the company has gathered enough pre-registrations, it will develop EU-specific content and services. Another plan is called Customer for Life. The idea is to offer additional services through the company's app, like storage and sharing of DNA information with other applications and medical providers. The company's contract says that it can keep customer DNA indefinitely, and use it to offer new services and market them to customers. It also says that customers agree not to withdraw direct marketing consent. Paul, the marketing director, suggests that the company should fully exploit these provisions, and that it can work around customers' attempts to withdraw consent because the contract invalidates them. The final plan is to develop a brand presence in the EU. The company has already begun this process. It is in the process of purchasing the naming rights for a building in Germany, which would come with a few offices that Who-R-U executives can use while traveling internationally. The office doesn't include any technology or infrastructure; rather, it's simply a room with a desk and some chairs. On a recent trip concerning the naming-rights deal, Bob's laptop is stolen. The laptop held unencrypted DNA reports on 5,000 Who-R-U customers, all of whom are residents of Canada. The reports include customer name, birthdate, ethnicity, racial background, names of relatives, gender, and occasionally health information. If Who-R-U decides to track locations using its app, what must it do to comply with the GDPR?
-
A
Get consent from the app users.
-
B
Provide a transparent notice to users.
-
C
Anonymize the data and add latency so it avoids disclosing real time locations.
-
D
Obtain a court order because location data is a special category of personal data.
Reveal answer details
Close answer details
Question 45
Single choice
Once an organization has conducted an internal investigation to determine the scope of a ransomware attack, what is the appropriate next step in the process?
-
A
Assess the risks associated with the breach and, if necessary, notify affected individuals and regulatory bodies within the relevant timeframes.
-
B
Notify law enforcement and consult with legal counsel to understand the implications of the breach and the notification requirements.
-
C
Inform all customers and the public via social media platforms to ensure rapid dissemination of relevant information.
-
D
Wait for law enforcement to provide guidance on notification procedures before taking any further action.
Reveal answer details
Close answer details
Question 46
Single choice
Higher fines are assessed for GDPR violations due to which of the following?
-
A
Failure to notify a supervisory authority and data subjects of a personal data breach
-
B
Violations of a data controller's obligations to obtain a child's consent
-
C
Failure to appoint a data protection officer.
-
D
Violations of a data subject"s rights
Reveal answer details
Close answer details
Question 47
Single choice
When collecting personal data in a European Union (EU) member state, what must a company do if it collects personal data from a source other than the data subjects themselves?
-
A
Inform the subjects about the collection
-
B
Provide a public notice regarding the data
-
C
Upgrade security to match that of the source
-
D
Update the data within a reasonable timeframe
Reveal answer details
Close answer details
|