Summer Certification Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code = getmirror

Pass the Exin Privacy & Data Protection PDPF Questions and answers with ExamsMirror

Practice at least 50% of the questions to maximize your chances of passing.
Exam PDPF Premium Access

View all detail and faqs for the PDPF exam


664 Students Passed

88% Average Score

96% Same Questions
Viewing page 3 out of 5 pages
Viewing questions 21-30 out of questions
Questions # 21:

The GDPR does not define privacy as a term but uses the concept implicitly throughout the text. What is a correct definition of privacy as implicitly used throughout the GDPR?

Options:

A.

The right to respect for one’s private and family life, home and personal correspondence

B.

The right not to be disturbed by uninvited people, nor being followed, spied on or monitored

C.

The fundamental right to protection of personal data, regardless of how it was obtained

D.

The right to freedom of opinion and expression and to seeking, receiving and imparting information

Questions # 22:

Which option below defines correctly data protection by design (from conception)?

Options:

A.

It’s a methodology of data protection according to its form

B.

It’s a concept that demonstrates the need to protect data since the beginning.

C.

It’s a methodology about how the data should be collected

D.

Only data that is required for processing should be processed

Questions # 23:

A person who works for a union took home a draft newsletter to finish it. The thumb drive containing the draft and contact list has been lost. To whom, among others, this data breach should be reported?

Options:

A.

To all members of the contact list

B.

To the Union staff

C.

To the police

Questions # 24:

What does the GDPR concept of ‘binding corporate rules’ (BCR) imply?

Options:

A.

A commission decision on the safety of data transfer to a third country

B.

A set of rules used by a group of enterprises concerning personal data protection in international transfers

C.

Measures to compensate for the lack of data protection in a third country

D.

Rules covering data transfers between third countries

Questions # 25:

One of the seven principles of data protection by design is Functionality - Positive-Sum, not Zero-Sum. What is the essence of this principle?

Options:

A.

If different types of legitimate objectives are contradictory, the privacy objectives must be given priority over other security objectives.

B.

Applied security standards must assure the confidentiality, integrity and availability of personal data throughout their lifecycle.

C.

Wherever possible, detailed privacy impact and risk assessments should be carried out and published, clearly documenting the privacy risks.

D.

When embedding privacy into a given technology, process, or system, it should be done in such a way that full functionality is not impaired.

Questions # 26:

A security breach has occurred in an information system that also holds personal data. According to the GDPR, what is the very first thing the controller must do?

Options:

A.

Assess the risk of adverse effects to the data subjects using a data protection impact assessment (DPIA)

B.

Ascertain whether the breach may have resulted in loss or unlawful processing of personal data

C.

Report the breach immediately to all data subjects and the relevant supervisory authority

D.

Assess whether personal data of a sensitive nature has or may have been unlawfully processed

Questions # 27:

In what way are online activities of people most effectively used by modern marketers?

Options:

A.

By analyzing the logs of the web server it can be seen which products are top sellers, allowing them to optimize their marketing campaigns for those products.

B.

By tagging users of social media, profiles of their online behavior can be created. These profiles are used to ask them to promote a product.

C.

By tagging visitors of web pages, profiles of their online behavior can be created. These profiles are sold and used in targeted advertisement campaigns.

Questions # 28:

What is the main purpose of cookies?

Options:

A.

Identify user preferences, identify the user and it can also save login to a website.

B.

Save the browser history, making it easier for the user to access the page again in the future.

C.

Display advertisements directed to the user, using information collected from the browser.

D.

Infect computers so that unsolicited advertisements are displayed in the browser.

Questions # 29:

Which of the parts below can implement data protection by design (from conception)?

Options:

A.

The data subject.

B.

The Data Protection Officer (DPO).

C.

The processor.

D.

The supervisory authority.

Questions # 30:

Organizations are obliged to keep a number of records to demonstrate compliance with the GDPR. Which record is not obligatory according to the GDPR?

Options:

A.

A record of notifications sent to the supervisory authority regarding processing of personal data

B.

A record of all intended processing together with the processing purpose(s) and legal justifications

C.

A record of processors including personal data provided and the period this data can be retained

D.

A record of data breaches with all relevant characteristics, including notifications

Viewing page 3 out of 5 pages
Viewing questions 21-30 out of questions
TOP CODES

TOP CODES

Top selling exam codes in the certification world, popular, in demand and updated to help you pass on the first try.