โ† All CSC Flashcard Decks

GDPR Data Protection Principles Flashcards

7 cards from real CSC practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 GDPR Data Protection Principles flashcards as text
  1. A processor sub-contracts data processing to a third party without the controller's written authorisation. Under GDPR, this most directly violates:

    Answer: The processor's obligation to act only on documented instructions and obtain prior controller authorisation for sub-processors

    Article 28 requires processors to obtain prior written authorisation from the controller before engaging sub-processors.

  2. When assessing whether a further processing purpose is compatible with the original purpose, GDPR Article 6(4) requires controllers to consider all EXCEPT:

    Answer: The revenue impact on the controller's business

    Revenue impact is not one of the compatibility factors; Article 6(4) focuses on purpose link, context, data nature, consequences, and safeguards.

  3. A US company processes EU residents' personal data. Under GDPR's territorial scope (Article 3), this company:

    Answer: Must comply with GDPR if it offers goods or services to, or monitors the behaviour of, EU residents

    GDPR applies to non-EU controllers that offer goods/services to EU residents or monitor their behaviour, regardless of where the controller is established.

  4. Under GDPR, which activity would most clearly satisfy the accuracy principle?

    Answer: Implementing a process allowing customers to update their contact details

    Providing data subjects a mechanism to update their information directly supports GDPR's accuracy principle, which requires data to be kept current.

  5. A Data Protection Impact Assessment (DPIA) is required under GDPR when processing is likely to result in:

    Answer: A high risk to the rights and freedoms of natural persons

    Article 35 mandates a DPIA before processing that is likely to result in a high risk to individuals' rights and freedoms, particularly for systematic profiling or large-scale sensitive data.

  6. Which GDPR principle most directly supports a data subject's right to obtain confirmation of whether their personal data is being processed?

    Answer: Transparency

    The transparency principle underpins the right of access, ensuring data subjects can confirm and understand how their data is being processed.

  7. An organisation conducts annual staff training on data handling, maintains a Record of Processing Activities (RoPA), and documents all DPIAs. These actions primarily demonstrate compliance with which GDPR principle?

    Answer: Accountability

    Training, RoPAs, and DPIAs are key accountability measures that demonstrate a controller's active responsibility for and compliance with GDPR obligations.