GDPR Data Management & Integration 3 — Questions and Answers
Question 1: A healthcare organisation integrates patient records with a research database. Which GDPR provision most directly permits processing special-category data for scientific research?
- Article 6(1)(a) — consent
- Article 9(2)(j) — scientific research with appropriate safeguards (Correct answer)
- Article 9(2)(a) — explicit consent only
- Article 6(1)(f) — legitimate interests
Correct answer: Article 9(2)(j) — scientific research with appropriate safeguards
Article 9(2)(j) allows processing special-category data for scientific research purposes, provided appropriate safeguards such as pseudonymisation are applied.
Question 2: A company uses pseudonymisation when integrating datasets. According to GDPR, pseudonymised data is best described as:
- Fully anonymous and outside the scope of GDPR
- Personal data that can no longer be attributed to a specific individual without additional information (Correct answer)
- Data that requires explicit consent to process
- Data that may only be stored within the EU
Correct answer: Personal data that can no longer be attributed to a specific individual without additional information
Recital 26 and Article 4(5) define pseudonymised data as personal data that cannot be attributed to a specific data subject without additional information held separately.
Question 3: During a master data management (MDM) initiative, an organisation plans to create a 'golden record' consolidating personal data from five source systems. What GDPR principle requires that only necessary data fields be included in the golden record?
- Accuracy
- Data minimisation (Correct answer)
- Storage limitation
- Transparency
Correct answer: Data minimisation
Article 5(1)(c) data minimisation requires that personal data be adequate, relevant, and limited to what is necessary for the specified purpose.
Question 4: An API integration passes personal data between two controllers' systems in real time. Which security measure is most important to implement under Article 32 of the GDPR?
- Storing API logs indefinitely for audit purposes
- Encrypting data in transit using TLS (Correct answer)
- Requiring the receiving controller to appoint a DPO
- Registering the API with the supervisory authority
Correct answer: Encrypting data in transit using TLS
Article 32 requires appropriate technical measures including encryption; TLS encryption protects personal data in transit between systems.
Question 5: A joint data integration project involves two separate companies both determining the purposes and means of processing. Under GDPR, they are classified as:
- Co-processors
- Joint controllers under Article 26 (Correct answer)
- Independent controllers with no special obligations to each other
- Sub-processors requiring separate DPAs
Correct answer: Joint controllers under Article 26
Article 26 defines joint controllers as two or more entities that jointly determine the purposes and means of processing and requires a transparent arrangement between them.
Question 6: A data warehouse retains personal data from closed customer accounts for seven years for tax compliance purposes. Which GDPR legal basis is most appropriate for this retention?
- Consent
- Legitimate interests
- Compliance with a legal obligation under Article 6(1)(c) (Correct answer)
- Performance of a contract
Correct answer: Compliance with a legal obligation under Article 6(1)(c)
Article 6(1)(c) permits processing necessary to comply with a legal obligation, such as statutory tax record-keeping requirements.
Question 7: Under GDPR's accountability principle, what document should an organisation maintain to demonstrate compliance in a complex multi-system data integration environment?
- A public privacy policy updated annually
- Records of Processing Activities (RoPA) under Article 30 (Correct answer)
- An ISO 27001 certificate
- A data breach register filed with the supervisory authority
Correct answer: Records of Processing Activities (RoPA) under Article 30
Article 30 requires controllers to maintain records of processing activities, which serve as a key accountability tool across all processing, including integrated data flows.
A healthcare organisation integrates patient records with a research database.
Which GDPR provision most directly permits processing special-category data for scientific research?