GDPR Specialist Principles and Concepts 1 — Questions and Answers
Question 1: What is the primary objective of the GDPR?
- Regulate e-commerce practices
- Facilitate international trade
- Protect personal data and privacy (Correct answer)
- Restrict government data access
Correct answer: Protect personal data and privacy
The General Data Protection Regulation (GDPR) is a comprehensive data protection law primarily aimed at enhancing the privacy rights of individuals within the European Union. Its core objective is to give individuals more control over their personal data and to standardize data protection across the EU.
Question 2: Which principle requires that data be collected for specific, explicit, and legitimate purposes?
- Data minimization
- Storage limitation
- Purpose limitation (Correct answer)
- Integrity and confidentiality
Correct answer: Purpose limitation
The principle of purpose limitation under GDPR mandates that personal data must be collected for specified, explicit, and legitimate purposes. Furthermore, it cannot be further processed in a manner that is incompatible with those original purposes, ensuring data is used only as intended and communicated to the data subject.
Question 3: Under GDPR, who is responsible for determining the purposes and means of data processing?
- Data processor
- Supervisory authority
- Data controller (Correct answer)
- IT service provider
Correct answer: Data controller
Under GDPR, the data controller is the entity that determines the purposes and means of processing personal data. They hold primary responsibility for compliance with GDPR principles and ensuring that all data processing activities are lawful and transparent.
Question 4: What does the principle of data minimization require?
- Collect all available data
- Retain data indefinitely
- Limit data collection to what is necessary (Correct answer)
- Share data across departments
Correct answer: Limit data collection to what is necessary
The principle of data minimization requires that personal data collected should be adequate, relevant, and limited to what is necessary in relation to the purposes for which they are processed. This prevents organizations from collecting excessive or irrelevant data, thereby reducing privacy risks.
Question 5: Which of the following is a lawful basis for processing personal data under GDPR?
- Personal interest
- Public review
- Consent (Correct answer)
- Speculative research
Correct answer: Consent
Consent is one of the six lawful bases for processing personal data under GDPR, requiring a clear affirmative act indicating agreement to the processing. For consent to be valid, it must be freely given, specific, informed, and unambiguous, and individuals must have the right to withdraw it at any time.
Question 6: What role does the Data Protection Officer (DPO) play under GDPR?
- Develops software solutions
- Handles HR tasks
- Monitors and advises on GDPR compliance (Correct answer)
- Manages marketing campaigns
Correct answer: Monitors and advises on GDPR compliance
A Data Protection Officer (DPO) is an expert on data protection law and practices, appointed to monitor an organization's compliance with GDPR. The DPO advises on data protection obligations, acts as a contact point for supervisory authorities, and informs employees about their responsibilities.
What is the primary objective of the GDPR?