PDPF Exam - Free Sample Questions & Answers
Preparing for the PDPF exam is simple with Certs Blitz. We offer easy-to-understand study materials that help you learn the most important exam topics. You can study using our PDF questions, practice online with a real exam-style test, or use the desktop practice software. Choose the study method that works best for you and prepare at your own pace.
At Certs Blitz, we keep our PDPF practice questions up to date. Whenever the exam syllabus or objectives change, we update our study materials so you always learn the latest topics. This helps you save time, avoid outdated content, and feel more confident when you take your exam.
Under what EU legislation is data transfer between the EEA and the U.S. A. allowed?
Correct Answer: A
Reference: https://ec.europa.eu/info/law/law-topic/data-protection/data-transfers-outside-eu_en
For processing of personal data to be legal, a number of requirements must be fulfilled. What is a requirement for lawful personal data processing?
Correct Answer: D
An architect, leaving a building site, puts his laptop for a moment beside his car on the road, while answering his phone. When driving away he sees in the mirror his laptop being crushed by an enormous lorry driving over it. All his files on the design of the building and the calculations he worked on are lost. His only consolation is that those were the only files on the device.
In terms of the GDPR, what happened?
Correct Answer: B
Which of the following options describes the concept of data minimization?
Correct Answer: C
n its Article 5, which deals with the Principles relating to the processing of personal data, paragraph 1, the GDPR describes:
1. Personal data shall be:
adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed
(data minimisation);
Article 5 mentions all GDPR principles for processing personal data.
The data minimization principle refers to the purpose of the law that only the data that is required for processing should be collected.
This is also favorable to businesses. The less data is collected, the less likely violations are to occur and consequently the impacts also decrease.
https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679
A processor is instructed to report on customers who bought a product both last month and at least once in the three months before that. Unfortunately, the processor makes a mistake and uses personal data collected by another controller for a different purpose. The mistake is found before the report is created, and nobody has access to personal date he or she should not have had access to. How should the processor act on this situation and what should the controller do, if anything?