GDPR Monitoring & Reporting Tools 2 — Questions and Answers
Question 1: Which GDPR article specifically requires controllers to implement appropriate technical and organizational measures to ensure processing security, which monitoring tools must support?
- Article 25
- Article 32 (Correct answer)
- Article 35
- Article 44
Correct answer: Article 32
Article 32 mandates appropriate technical and organizational security measures, which monitoring tools must help enforce and document.
Question 2: A DPO uses a compliance dashboard showing a 'data map.' What is the primary GDPR purpose of maintaining such a data map?
- To calculate storage costs
- To support Records of Processing Activities under Article 30 (Correct answer)
- To automate consent withdrawal
- To generate breach notification templates
Correct answer: To support Records of Processing Activities under Article 30
Data maps underpin the Records of Processing Activities (RoPA) required by GDPR Article 30, documenting all processing operations.
Question 3: When a monitoring tool logs access to personal data, which GDPR principle does this practice most directly support?
- Data minimisation
- Storage limitation
- Accountability (Correct answer)
- Purpose limitation
Correct answer: Accountability
Access logging demonstrates accountability by creating evidence that the controller can use to show compliance with GDPR obligations.
Question 4: A SIEM system alerts on anomalous bulk exports of personal data. Under GDPR, the controller must assess whether this constitutes a personal data breach within how many hours of becoming aware?
- 24 hours
- 48 hours
- 72 hours (Correct answer)
- 96 hours
Correct answer: 72 hours
Article 33 requires notification to the supervisory authority within 72 hours of becoming aware of a personal data breach.
Question 5: Which metric is LEAST useful in a GDPR compliance monitoring dashboard for assessing data subject rights fulfillment?
- Average time to respond to access requests
- Percentage of requests responded to within 30 days
- Number of server CPU cycles used per request (Correct answer)
- Volume of erasure requests received
Correct answer: Number of server CPU cycles used per request
CPU cycles are an infrastructure metric with no direct bearing on GDPR data subject rights compliance obligations.
Question 6: An organization uses automated cookie scanning tools. What GDPR requirement does this tool primarily help fulfill?
- Lawful basis documentation for HR data
- Transparency and consent management for tracking technologies (Correct answer)
- Data retention schedule enforcement
- Cross-border transfer impact assessments
Correct answer: Transparency and consent management for tracking technologies
Cookie scanners help ensure transparency and valid consent for non-essential cookies, aligning with GDPR consent requirements and ePrivacy rules.
Question 7: A processor must allow and contribute to audits conducted by the controller under GDPR. Which article imposes this obligation?
- Article 28 (Correct answer)
- Article 30
- Article 37
- Article 46
Correct answer: Article 28
Article 28(3)(h) requires that processors make available all information necessary and allow for audits and inspections by the controller.
Which GDPR article specifically requires controllers to implement appropriate technical and organizational measures to ensure processing security, which monitoring tools must support?