Quiz Summary
0 of 19 Questions completed
Questions:
Information
You have already completed the quiz before. Hence you can not start it again.
Quiz is loading…
You must sign in or sign up to start the quiz.
You must first complete the following:
Results
Results
0 of 19 Questions answered correctly
Your time:
Time has elapsed
You have reached 0 of 0 point(s), (0)
Earned Point(s): 0 of 0, (0)
0 Essay(s) Pending (Possible Point(s): 0)
Average score |
|
Your score |
|
Categories
- Not categorized 0%
- 1
- 2
- 3
- 4
- 5
- 6
- 7
- 8
- 9
- 10
- 11
- 12
- 13
- 14
- 15
- 16
- 17
- 18
- 19
- Current
- Review
- Answered
- Correct
- Incorrect
-
Question 1 of 19
1. Question
1 point(s)The GDPR is a future proof directive that must be abided by each EU member state and by any organisation that trades within the EU or with EU data.
CorrectIncorrect -
Question 2 of 19
2. Question
1 point(s)In the UK, which one of the following regulations is replaced by the GDPR?
CorrectIncorrect -
Question 3 of 19
3. Question
1 point(s)The data controller says how and why personal data is processed and the data processor acts on the controller’s behalf.
CorrectIncorrect -
Question 4 of 19
4. Question
1 point(s)Which of the following are reasons for implementing the GDPR?
CorrectIncorrect -
Question 5 of 19
5. Question
1 point(s)Under the GDPR, an organisation must have an individual’s ‘explicit consent before they can use their personal data.
CorrectIncorrect -
Question 6 of 19
6. Question
1 point(s)Which one of the following assessments is a process which assists organisations to identify and minimise privacy risks in new data system projects?
CorrectIncorrect -
Question 7 of 19
7. Question
1 point(s)Organisations can appoint a Data Protection Officer (DPO) even when the GDPR doesn’t oblige them to do so.
CorrectIncorrect -
Question 8 of 19
8. Question
1 point(s)Organisations can appoint a Data Protection Officer (DPO) even when the GDPR doesn’t oblige them to do so.
CorrectIncorrect -
Question 9 of 19
9. Question
1 point(s)The Information Commissioner’s Office (ICO) must be informed of a personal data breach with how many hours?
CorrectIncorrect -
Question 10 of 19
10. Question
1 point(s)Under the GDPR’s two tier fine system, if a data breach occurs that puts what authorities deem to be highly important data at risk. The data controller or processor will be subject to a tier one fine up to:
CorrectIncorrect -
Question 11 of 19
11. Question
1 point(s)Under the GDPR’s two tier fine system, if a data breach occurs that puts what authorities deem to be less important data at risk. The data controller or processor will be subject to a tier two fine up to:
CorrectIncorrect -
Question 12 of 19
12. Question
1 point(s)Following privacy by design principles helps to identify potential privacy issues at an early and less costly stage in the design and development process.
CorrectIncorrect -
Question 13 of 19
13. Question
1 point(s)The GDPR requires that information provided by an organisation to individuals about the processing of personal data should be:
CorrectIncorrect -
Question 14 of 19
14. Question
1 point(s)The GDPR stipulates that information must be provided without delay and at the latest within three months of receipt of the request.
CorrectIncorrect -
Question 15 of 19
15. Question
1 point(s)Read the following sentences about the Right of Access and select the ones that you think are true and which are false.Organisations must provide a copy of the information free of charge
CorrectIncorrect -
Question 16 of 19
16. Question
1 point(s)The right to erasure provides and absolute right for individuals to be forgotten.
CorrectIncorrect -
Question 17 of 19
17. Question
1 point(s)Which one of the following is a machine readable digital file format that can be used to implement data portability?
CorrectIncorrect -
Question 18 of 19
18. Question
1 point(s)Read the following sentences about the Right to Object and select the ones that you think are true and which are false.
1. The processing of personal data for direct marketing purposes must stop within 48 hours from when the organisation receives an objection.
2. An organisation must deal with an objection to processing for direct marketing at any time and free of charge.
3. Individuals must be informed of their right to object ‘at the point of first communication’ and in the organisation’s privacy notice.
4. This must be ‘explicitly brought to the attention of individuals within 30 days and shall be presented clearly and separately from any other information.
CorrectIncorrect -
Question 19 of 19
19. Question
1 point(s)Where an organisation’s processing operation includes automatic decision making, individuals have the right not to be subject to a decision when:
CorrectIncorrect