Summer Certification Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code = getmirror

Pass the Exin Privacy & Data Protection PDPF Questions and answers with ExamsMirror

Practice at least 50% of the questions to maximize your chances of passing.
Exam PDPF Premium Access

View all detail and faqs for the PDPF exam


664 Students Passed

88% Average Score

96% Same Questions
Viewing page 4 out of 5 pages
Viewing questions 31-40 out of questions
Questions # 31:

Subcontracting treatment is regulated by contract or other regulatory act under Union or Member State law, which links the processor to the controller.

What this contract or other regulatory act stipulates?

Options:

A.

A process for testing, assessing and regularly evaluating the effectiveness of technical and organizational measures to ensure safe treatment.

B.

The processor assists the driver through technical and organizational measures to enable it to fulfill its obligation to respond to requests from data subjects.

C.

The description of categories of data subjects and categories of personal data

D.

The purpose of data processing

Questions # 32:

What is the purpose of Data Lifecycle Management (DLM)?

Options:

A.

Ensure data integrity and its periodic update

B.

Ensure data confidentiality and availability throughout its useful life.

C.

Ensure that the processing of personal data, throughout its useful life complies with the GDPR

D.

Ensure data confidentiality throughout its useful life, from collection to deletion.

Questions # 33:

Which EU legislation allows data to be transferred between the European Economic Area (EEA) and the United States (USA)?

Options:

A.

A suitability decision based on the Privacy Shield program

B.

A transfer made on the basis of World Trade Organization legislation.

C.

European Union Directive 95/46 / EC.

D.

A transfer made under UN law.

Questions # 34:

What is the most important difference between the 95/46/EC and the GDPR?

Options:

A.

95/46/EC applies as law in all EEA member states while the GDPR is a guidance.

B.

95/46/EC applies to processing of data on EEA residents worldwide and the GDPR does not.

C.

The GDPR applies as law in all EEA member states while 95/46/EC is a guidance.

D.

The GDPR applies to persons and organizations which process personal data within EEA member states.

The scope of 95/46/EC is more restricted in this aspect.

Questions # 35:

A controller wants to outsource processing of personal data to a processor. What must be done before outsourcing?

Options:

A.

The processor must show the controller that all demands agreed in the service level agreement (SLA) are met.

B.

The controller and processor must draft and sign a written contract guaranteeing the confidentiality of the data.

C.

The controller must ask the supervisory authority for permission to outsource the processing of the data.

D.

The controller must ask the supervisory authority if the agreed written contract is compliant with the regulations.

Questions # 36:

What is the main use of a persistent cookie?

Options:

A.

To save the pages a user has bookmarked in the user’s browser history

B.

To record every keystroke made by a computer user to find out passwords

C.

To ensure that the user’s personal data are stored securely on the server

D.

To personalize the user’s experience of the website during the next visit

Questions # 37:

A German company wants to enter into a binding contract with a processor in the Netherlands for the processing of sensitive personal data of German data subjects. The Dutch Supervisory Authority is informed of the type of data and the aims of the processing, including the contract describing what data will be processed and what data protection procedures and practices will be in place.

According to the GDPR, what should the Dutch Supervisory Authority do in this scenario?

Options:

A.

Report the data processing to the German Supervisory Authority and leave the supervising to them.

B.

Supervise the processing of personal data in accordance with Dutch Law.

C.

Supervise the processing of personal data in accordance with German Law.

D.

The Dutch Supervisory Authority should check that adequate binding contracts are in place. The German Supervisory Authority should supervise.

Questions # 38:

Racial or ethnic origin, political opinions, religious or philosophical beliefs, or union membership, as well as the processing of genetic data, biometric data, health data or data relating to a person’s sexual life or sexual orientation.

What does this sentence above refer to?

Options:

A.

Available personal data categories.

B.

Rights categories of data subjects.

C.

Categories of purposes for the processing of personal data.

D.

Personal data categories.

Questions # 39:

What is a responsibility of Supervisory Authorities in EEA countries?

Options:

A.

Research on security breaches of corporate information

B.

Supervision of all data processing operations controlled by a controller in an EEA country

C.

Supervision of all data processing operations where the data subjects are residents of an EEA country

Questions # 40:

One of the basic principles of the General Data Protection Regulation (GDPR) is subsidiarity.

What is subsidiarity to GDPR?

Options:

A.

Personal data can only be collected for explicit, legitimate and specific purposes and cannot be processed for any other purpose.

B.

Only the personal data needed to achieve a specific purpose should be collected.

C.

The least privacy-violating means should be used when processing personal data.

D.

Personal data must be kept for a period not longer than necessary.

Viewing page 4 out of 5 pages
Viewing questions 31-40 out of questions
TOP CODES

TOP CODES

Top selling exam codes in the certification world, popular, in demand and updated to help you pass on the first try.