Summer Certification Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code = getmirror

Pass the Exin Privacy & Data Protection PDPF Questions and answers with ExamsMirror

Practice at least 50% of the questions to maximize your chances of passing.
Exam PDPF Premium Access

View all detail and faqs for the PDPF exam


664 Students Passed

88% Average Score

96% Same Questions
Viewing page 2 out of 5 pages
Viewing questions 11-20 out of questions
Questions # 11:

Which of the following options describes the concept of data minimization?

Options:

A.

It is the minimization of data storage locations.

B.

It is the decrease in the space allocated for data storage.

C.

It is the limitation of data to the purposes for which it is treated.

D.

It is the use of data for the shortest possible time.

Questions # 12:

What is the essence of the principle ‘Full Lifecycle Protection’?

Options:

A.

Delivering the maximum degree of data protection by default, ensuring that personal data are automatically protected in any given IT system or business practice.

B.

Ensuring that whatever business practice or technology is involved, processing is done according to the stated objectives, subject to independent verification.

C.

Embedding security measures to protect the data from the moment it is collected, throughout processing until it is destroyed at the end of the process.

D.

Prioritizing the protection of the interests of the individual by offering for example strong privacy defaults, appropriate notice or empowering user-friendly options.

Questions # 13:

Which of the following types of transfers of personal data outside the European Economic Area (EEA) is allowed?

Options:

A.

Transfer between country governments.

B.

Transfers subject to the law of the countries involved.

C.

Transfers conducted through Standard Contractual Clauses.

D.

Transfers conducted under Compulsory Corporate Rules.

Questions # 14:

Which of these should appear in a Data Protection Impact Assessment (DPIA) according to the General Data Protection Regulation (GDPR)?

Options:

A.

An assessment of the need and proportionality of treatment operations in relation to the objectives.

B.

Data Protection Officer (DPO) contact and responsibilities.

C.

An inventory and the flow of personal data within the organization.

D.

A survey of other laws that must be taken into account in addition to the GDPR.

Questions # 15:

Which cause is a data breach according to the GDPR?

Options:

A.

illegally obtained corporate data from a human resources management system

B.

Personal data is processed without a binding contract.

C.

Personal data is processed by anyone other than the controller, processor or, possibly, subprocessor

D.

The operation of a vulnerable server in the internal network of the processor

Questions # 16:

How should data protection between the processor and controller be regulated in accordance with the General Data Protection Regulation (GDPR)?

Options:

A.

Contract

B.

Supervisory Authority endorsement.

C.

Compulsory Corporate Rules.

D.

Standard contractual clauses.

Questions # 17:

The illegal collection, storage, modification, disclosure or dissemination of personal data is an offense under European law.

What kind of offense is this?

Options:

A.

An offense related to content

B.

An offense to intellectual property

C.

An economic offense

D.

An offense to privacy

Questions # 18:

What is the purpose of a data protection audit by the supervisory authority?

Options:

A.

To monitor and enforce the application of the GDPR by assessing that processing is performed in compliance with the GDPR.

B.

To fulfill the obligation in the GDPR to implement appropriate technical and organizational measures for data protection.

C.

To advise the controller on the mitigation of privacy risks to protect the controller from liability claims for

non-compliance.

Questions # 19:

A company is planning to process personal data. The recently appointed data protection officer (DPO) executes a data protection impact assessment (DPIA). The DPO finds that all computers have a setting causing monitors to show a screen saver after five seconds of inaction. However, the computers are not locked automatically. When employees leave their desk, they usually do not lock their computers either. What is this an example of?

Options:

A.

Security incident

B.

Personal data breach

C.

Security vulnerability

D.

Data access

Questions # 20:

A company located in France wishes to enter into a compulsory contract with a processor located in Portugal. This contract aims to process sensitive French personal data. The Portuguese Supervisory Authority is informed about this contract and the type of processing.

How should Portuguese Supervisory Authority proceed, in accordance with the General Data Protection Regulation (GDPR)?

Options:

A.

Supervise the processing of personal data according to the guidelines of the Supervisory Authority of Portugal.

B.

Report the data processing to the French Supervisory Authority, which must take over the supervision.

C.

Verify that adequate compulsory contracts have been established and leave supervision to the French Supervisory Authority.

D.

Supervise the processing of personal data in accordance with the French Supervisory Authority legislation.

Viewing page 2 out of 5 pages
Viewing questions 11-20 out of questions
TOP CODES

TOP CODES

Top selling exam codes in the certification world, popular, in demand and updated to help you pass on the first try.