Weekend Special 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: Board70

PDPF Exam Dumps - Exin Privacy & Data Protection Questions and Answers

Question # 4

When is a Data Protection Impact Assessment (DPIA) under the General Data Protection Regulation (GDPR) mandatory?

Options:

A.

Application of new technologies that may imply a high risk to the rights and freedoms of data subjects.

B.

There is no security policy and information security risk analysis.

C.

In all types of personal data processing.

Buy Now
Question # 5

To plan the amount of parking space needed, a local government monitors and saves the license plate number of every car that enters and leaves the city center. They have obtained permission to collect data on the number of cars present in the city center. By comparing the license plate time of entry and exit the number of cars present every moment of each day is calculated. Each month a report is created detailing the average number of cars in the city center at specific moments for every day of the week. At every entrance to the city center, a billboard clearly states what data is collected by whom, the purpose of the processing and the fact that the license plate numbers are saved securely for up to two years, because the measurements will be repeated next year. Which of the basic principles for legitimate processing of personal data is violated in this scenario?

Options:

A.

Personal data are processed in a manner that ensures appropriate security of the personal data.

B.

Personal data are processed in a transparent manner in relation to the data subject

C.

Personal data are kept in a form permitting identification of data subjects for no longer than is necessary.

D.

Personal data are collected for specified, explicit and legitimate purposes and not further processed.

Buy Now
Question # 6

According to Article.33 of the GDPR the controller shall without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach to the supervisory authority. What is the maximum penalty for non-compliance with this notification obligation?

Options:

A.

€ 10.000.000 or 2% of the annual global turnover, whichever is higher

B.

€ 20.000.000 or 4% of the annual global turnover, whichever is higher

C.

Up to € 500.000 with a minimum of € 120.000

D.

Up to € 820.000 with a minimum of € 350.000

Buy Now
Question # 7

Personal data as defined in the GDPR can be divided into several types. One of these types is described: Data that directly or indirectly reveal someone’s racial or ethnic background, political, philosophical, religious views, union affiliation and data related to health or sex life and sexual orientation. What type of personal data is this?

Options:

A.

Direct personal data

B.

Indirect personal data

C.

Pseudonymized data

D.

Special category personal data

Buy Now
Question # 8

When personal data are processed, who is ultimately responsible for demonstrating compliance with the GDPR?

Options:

A.

Data protection officer (DPO)

B.

Supervisory authority

C.

Processor

D.

Controller

Buy Now
Question # 9

Which of the options below best represents data protection by design?

Options:

A.

It aims to incorporate security measures to protect data from the moment it is collected, throughout the processing and until its destruction at the end of the process

B.

It aims to ensure that personal data is automatically part of a protection process.

C.

It aims to create privacy impact analysis procedures (DPIA), notifications of breaches of privacy and fulfil requests from data subjects.

Buy Now
Question # 10

What is the purpose of Data Lifecycle Management (DLM)?

Options:

A.

Ensure data integrity and its periodic update

B.

Ensure data confidentiality and availability throughout its useful life.

C.

Ensure that the processing of personal data, throughout its useful life complies with the GDPR

D.

Ensure data confidentiality throughout its useful life, from collection to deletion.

Buy Now
Question # 11

The Control Authority may impose fines on organizations that are not meeting the mandatory requirements of the General Data Protection Regulation (GDPR).

Options:

A.

False

B.

True

Buy Now
Question # 12

Which cause is a data breach according to the GDPR?

Options:

A.

illegally obtained corporate data from a human resources management system

B.

Personal data is processed without a binding contract.

C.

Personal data is processed by anyone other than the controller, processor or, possibly, subprocessor

D.

The operation of a vulnerable server in the internal network of the processor

Buy Now
Question # 13

What is the term used in the General Data Protection Regulation (GDPR) for the disclosure of, or unauthorized access to, personal data?

Options:

A.

Security incident

B.

Incident

C.

Breach of confidentiality

D.

Data breach

Buy Now
Exam Code: PDPF
Exam Name: Privacy and Data Protection Foundation
Last Update: Feb 22, 2025
Questions: 149
PDPF pdf

PDPF PDF

$25.5  $84.99
PDPF Engine

PDPF Testing Engine

$28.5  $94.99
PDPF PDF + Engine

PDPF PDF + Testing Engine

$40.5  $134.99