โ† All CSC Flashcard Decks

GDPR Data Protection Principles Flashcards

7 cards from real CSC practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 GDPR Data Protection Principles flashcards as text
  1. Under GDPR's storage limitation principle, personal data must be kept in a form that permits identification of data subjects for no longer than:

    Answer: No longer than is necessary for the purposes for which it is processed

    The storage limitation principle requires that personal data is kept only as long as necessary for its specified purpose, after which it must be deleted or anonymized.

  2. A healthcare provider collects patient data for treatment but later wants to use it for marketing. Under GDPR's purpose limitation principle, this secondary use is:

    Answer: Permitted only with a new explicit consent from patients

    Purpose limitation prohibits using data for incompatible secondary purposes; marketing is incompatible with treatment, so fresh explicit consent is required.

  3. Which GDPR principle requires that personal data must be accurate and, where necessary, kept up to date?

    Answer: Accuracy

    The accuracy principle mandates that inaccurate personal data must be erased or rectified without delay.

  4. An e-commerce site collects a customer's full medical history during checkout 'just in case it's useful later.' Which GDPR principle is most directly violated?

    Answer: Data minimisation

    Data minimisation requires that only data adequate, relevant, and limited to what is necessary for the specified purpose is collected.

  5. The GDPR principle of 'integrity and confidentiality' most directly requires controllers to:

    Answer: Ensure data is processed using appropriate technical and organisational security measures

    Integrity and confidentiality (security principle) mandates appropriate technical and organisational measures to protect data against unauthorised access, loss, or destruction.

  6. Under the accountability principle, which of the following best demonstrates compliance?

    Answer: Maintaining documented records of processing activities and impact assessments

    Accountability requires controllers to be able to demonstrate compliance through records, policies, DPIAs, and other documented evidence.

  7. A company pseudonymises customer data before using it for analytics. Under GDPR, pseudonymised data is:

    Answer: Still personal data if re-identification is possible

    Pseudonymised data remains personal data under GDPR because re-identification is possible when combined with additional information held by the controller.

GDPR Data Protection Principles Flashcards โ€” CSC Study Cards with Answers