GDPR Specialist Compliance and Enforcement 1 — Questions and Answers
Question 1: What is the role of a supervisory authority under GDPR?
- Create website content
- Monitor and enforce GDPR compliance (Correct answer)
- File taxes
- Issue business licenses
Correct answer: Monitor and enforce GDPR compliance
Supervisory authorities are independent public bodies established in each EU Member State to oversee and enforce GDPR. Their primary role involves monitoring organizations' compliance, investigating complaints from data subjects, and taking corrective actions, including imposing fines, when violations occur. They act as the primary protectors of individuals' data protection rights.
Question 2: Which body ensures consistent application of GDPR across the EU?
- European Parliament
- European Data Protection Board (Correct answer)
- Court of Justice
- Interpol
Correct answer: European Data Protection Board
The European Data Protection Board (EDPB) is an independent body that ensures the consistent application of GDPR across the EU. It comprises representatives from national supervisory authorities and the European Data Protection Supervisor. The EDPB issues guidelines, recommendations, and best practices to harmonize the interpretation and enforcement of data protection law throughout the Union.
Question 3: What can supervisory authorities do when a GDPR violation occurs?
- Close the business permanently
- Recommend a vacation
- Impose corrective measures and fines (Correct answer)
- Award company bonuses
Correct answer: Impose corrective measures and fines
When a GDPR violation occurs, supervisory authorities have significant powers to impose corrective measures and administrative fines. These measures can include warnings, reprimands, orders to rectify or erase data, and substantial financial penalties. The aim is to ensure compliance, deter future infringements, and protect the rights of data subjects.
Question 4: What is the maximum fine for serious GDPR infringements?
- €100,000
- €1 million
- €20 million or 4% of global turnover (Correct answer)
- 5% of net profit
Correct answer: €20 million or 4% of global turnover
For serious GDPR infringements, such as violations of data subjects' rights or core processing principles, the maximum administrative fine can be up to €20 million or 4% of the company's total worldwide annual turnover from the preceding financial year, whichever is higher. This significant penalty underscores the importance of data protection and acts as a strong deterrent against non-compliance.
Question 5: What must organizations demonstrate to show GDPR compliance?
- Annual stock reports
- Marketing performance
- Effective data protection policies and practices (Correct answer)
- Quarterly income increases
Correct answer: Effective data protection policies and practices
To demonstrate GDPR compliance, organizations must implement and maintain effective data protection policies and practices. This includes having clear internal procedures for data handling, conducting Data Protection Impact Assessments (DPIAs), maintaining records of processing activities, and ensuring appropriate technical and organizational security measures are in place. Proof of these measures is essential for accountability.
Question 6: How does GDPR ensure accountability?
- By allowing flexible interpretation
- Through randomized inspections
- Through mandatory documentation and audits (Correct answer)
- Via annual tax reports
Correct answer: Through mandatory documentation and audits
GDPR ensures accountability by requiring organizations to maintain comprehensive documentation of their data processing activities, such as records of processing, data protection impact assessments, and data breach notifications. Furthermore, supervisory authorities can conduct audits to verify compliance. This mandatory documentation and the potential for audits compel organizations to not only implement data protection measures but also to be able to demonstrate their effectiveness.
What is the role of a supervisory authority under GDPR?