Certs Vault
See all results for ""
Home Exams
CRISC ISACA CISSP ISC2 200-301 Cisco SY0-701 CompTIA AZ-104 Microsoft AI-900 Microsoft AIGP IAPP 1Z0-1067-26 Oracle View All Exams →
Sign in Create account

Privacy and Data Protection Foundation PDPF Exam Questions

Preparing for the PDPF exam is simple with Certs Vault. We offer easy-to-understand study materials that help you learn the most important exam topics. You can study using our PDF questions, practice online with a real exam-style test, or use the desktop practice software. Choose the study method that works best for you and prepare at your own pace.

At Certs Vault, we keep our PDPF practice questions up to date. Whenever the exam syllabus or objectives change, we update our study materials so you always learn the latest topics. This helps you save time, avoid outdated content, and feel more confident when you take your exam.

Download Exam View Entire Exam
Page: 1 / 1
Question #1 (Topic: Demo Questions)

Under what EU legislation is data transfer between the EEA and the U.S. A. allowed?

A.

An adequacy decision based on the Privacy Shield program

B.

An adequacy decision by reason of US domestic legislation

C.

The Transatlantic Trade an Investment Partnership (TTIP)

D.

The U.S.A.’s commitment to join the European Economic Area

Correct Answer: A
Explanation:

Reference: https://ec.europa.eu/info/law/law-topic/data-protection/data-transfers-outside-eu_en

Question #2 (Topic: Demo Questions)

For processing of personal data to be legal, a number of requirements must be fulfilled. What is a requirement for lawful personal data processing? 

A.

A ‘code of conduct’, describing what the processing exactly entails, must be in place.

B.

The data subject must have given consent, prior to the processing to begin. 

C.

The processing must be reported to and allowed by the Data Processing Authority

D.

There must be a legitimate ground for the processing of personal data.

Correct Answer: D
Question #3 (Topic: Demo Questions)

An architect, leaving a building site, puts his laptop for a moment beside his car on the road, while answering his phone. When driving away he sees in the mirror his laptop being crushed by an enormous lorry driving over it. All his files on the design of the building and the calculations he worked on are lost. His only consolation is that those were the only files on the device.

In terms of the GDPR, what happened?

A.

a data breach

B.

a security incident

C.

a security issue

D.

a vulnerability

Correct Answer: B
Question #4 (Topic: Demo Questions)

Which of the following options describes the concept of data minimization?

A.

It is the minimization of data storage locations.

B.

It is the decrease in the space allocated for data storage.

C.

It is the limitation of data to the purposes for which it is treated.

D.

It is the use of data for the shortest possible time.

Correct Answer: C
Explanation:

n its Article 5, which deals with the Principles relating to the processing of personal data, paragraph 1, the GDPR describes:

1. Personal data shall be:

adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed

(data minimisation);

Article 5 mentions all GDPR principles for processing personal data.

The data minimization principle refers to the purpose of the law that only the data that is required for processing should be collected.

This is also favorable to businesses. The less data is collected, the less likely violations are to occur and consequently the impacts also decrease.


https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679

Question #5 (Topic: Demo Questions)

A processor is instructed to report on customers who bought a product both last month and at least once in the three months before that. Unfortunately, the processor makes a mistake and uses personal data collected by another controller for a different purpose. The mistake is found before the report is created, and nobody has access to personal date he or she should not have had access to. How should the processor act on this situation and what should the controller do, if anything?

A.

The processor must notify the controller and the controller must notify the Data Protection Authority of a data breach. 

B.

The processor must notify the controller of a data breach. The controller must assess the possible risk to the data subjects.

C.

The processor must notify the Data Protection Authority of a data breach. The controller must execute a PIA to assess the risk to data subjects.

D.

The processor must restart processing using the right data. There is no need for the controller to act.

Correct Answer: B
Download Exam
Page: 1 / 1
Next Page