GDPR Test

Who is the single supervisory authority in the UK under the GDPR?
ICO
PRA
FCA
ISO
When must high risk data security breaches be reported to the ICO?
24 hours
72 hours
36 hours
One week
Which one of the following methods for obtaining consent will be unacceptable under the GDPR?
Tick box settings
An unsubscribe option
An opt-in tick box
A verbal agreement
What is the name given by the GDPR for the deletion of all personal data?
The right to objection
The right to withdraw consent
The right to access
The right to be forgotten
Who has overall accountability for compliance with the GDPR?
The data controller
The ICO
The data processor
The data subject
Under which of the following cloud computing model, user has little or no influence how input data is processed
Iaas
Paas
Saas
None of these
What is an internet crime in which someone masquerades as a trustworthy entity in some form of electronic communication
Spyware
Phishing
Malware
Pharming
Documenting processing activities under GDPR, is useful because
Demonstrate compliance
All of these
Legal requirement
Supports good data governance
Data protection by design is applicable to
Physical design
Developing new IT systems-services
Developing organisation polices
All of these
Which one of the following would be classified as sensitive personal data?
Address
CCTV video
Name
Religion
How many key principles are there under the Data Protection Act 2018?
5
7
10
14
After you have finished using someone's personal data, what should you do with it?
Pass it to someone else
Give it back to the owner
Securely delete or destroy it
Throw it out
If someone makes a data erasure request, how long do you have to notify them of your intended actions?
7 days
8 days
One month
One year
What is the GDPR?
A European Union regulation that aims to standardise the governance of personal information, particularly in terms of the security and protection of personal data.
A European regulation on data sharing within companies.
A European law obliging major browsers to comply on the use of personal data.
What does the GDPR require by law?
Organisations must keep data on European Internet users for a minimum of 5 years.
Organisations must put in place technical and organisational measures to continuously ensure optimal data protection and be able to demonstrate this by documenting their compliance.
Companies must share all user data with the European institutions in the interests of transparency.
How does the GDPR define ‘personal data’?
Your personal bank details and postal address
Any information relating to an identified or identifiable natural person
Your IP addresses and all personal online information
Who is primarily concerned by the GDPR?
Company employees.
EU citizens and all bodies processing their data.
The major tech companies
What is considered as lawful consent in the GDPR?
A continuation of navigation on a site or a mobile application by a simple scroll.
The simple act of downloading a document from a site or mobile application.
A clear affirmative act by which the person freely expresses, in a specific and informed manner, their consent to data processing.
Out of the data gathered by your digital analytics provider, which of the following categories of data are considered to be of a personal nature?
IP addresses, cookies, name of the site consulted and time of page consultation.
Cookies only.
IP addresses only.
In digital analytics, how long should data be kept?
6 months.
37 months.
To be defined on a case-by-case basis by each organisation.
What does the acronym DPO stand for?
Data Positioning Officer
Data Preservation Officer
Data Protection Officer
One of the obligations of the GDPR is to maintain records of processing activity. What should this document contain in particular?
The list of all subcontractors involved in the processing operation
The volume of data processed
The purposes of the processing operation, a description of the categories of data subjects and categories of personal data
As data controller, what should you expect from your digital analytics solution provider?
That it gives some advice on the security of your data.
That it attempts to ensure your full ownership of the data collected on your behalf.
That it provides a complete, clear and comprehensible data processing contract
What is privacy-by-design?
A methodology for documenting all compliance actions initiated by data controllers.
An approach to integrating privacy protection into the design and architecture specifications of new systems and processes.
A principle aimed at protecting data sharing within companies.
{"name":"GDPR Test", "url":"https://www.quiz-maker.com/QPREVIEW","txt":"Who is the single supervisory authority in the UK under the GDPR?, When must high risk data security breaches be reported to the ICO?, Which one of the following methods for obtaining consent will be unacceptable under the GDPR?","img":"https://www.quiz-maker.com/3012/images/ogquiz.png"}
Powered by: Quiz Maker