GDPR Monitoring & Reporting Tools 3 — Questions and Answers
Question 1: Under GDPR, which document produced by a monitoring tool serves as primary evidence during a supervisory authority inspection of processing activities?
- Network topology diagram
- Records of Processing Activities (RoPA) (Correct answer)
- Employee org chart
- IT asset register
Correct answer: Records of Processing Activities (RoPA)
The RoPA required by Article 30 is the core compliance document inspectors examine to understand the controller's processing landscape.
Question 2: A privacy monitoring tool identifies that a vendor is transferring EU personal data to a country without an adequacy decision and without SCCs. This represents a violation of which GDPR chapter?
- Chapter II — Principles
- Chapter III — Data Subject Rights
- Chapter V — Transfers to Third Countries (Correct answer)
- Chapter VII — Cooperation
Correct answer: Chapter V — Transfers to Third Countries
Chapter V (Articles 44-49) governs transfers of personal data to third countries and requires an appropriate safeguard such as adequacy decisions or SCCs.
Question 3: Which feature of a Data Loss Prevention (DLP) tool is most directly aligned with GDPR's data minimisation principle?
- Blocking transmission of files containing excessive personal data fields (Correct answer)
- Encrypting all outbound emails
- Logging user login times
- Scanning for malware attachments
Correct answer: Blocking transmission of files containing excessive personal data fields
Blocking transmission of files with excessive personal data enforces data minimisation by preventing unnecessary sharing of personal data.
Question 4: A GDPR monitoring platform shows that consent records for a marketing list are 18 months old with no re-confirmation. What risk does this most directly flag?
- Breach of storage limitation
- Stale consent that may no longer be freely given, specific, or informed (Correct answer)
- Missing processor agreement
- Failure to appoint a DPO
Correct answer: Stale consent that may no longer be freely given, specific, or informed
Consent must remain valid over time; aging records without re-confirmation risk failing the GDPR standards of being freely given, specific, informed, and unambiguous.
Question 5: An audit log monitoring tool flags that a system administrator accessed patient medical records outside their job role. Under GDPR, medical data is classified as:
- Ordinary personal data
- Sensitive data under Article 9 (special category) (Correct answer)
- Anonymous data exempt from GDPR
- Pseudonymous data requiring less protection
Correct answer: Sensitive data under Article 9 (special category)
Health data is explicitly listed as special category data under Article 9, requiring additional legal bases and heightened protection.
Question 6: A compliance tool generates a 'consent withdrawal rate' report. Which GDPR principle does monitoring this metric primarily support?
- Storage limitation
- Integrity and confidentiality
- Lawfulness — ensuring ongoing valid consent basis (Correct answer)
- Accuracy
Correct answer: Lawfulness — ensuring ongoing valid consent basis
Tracking consent withdrawal ensures the controller removes withdrawn subjects from processing, maintaining a lawful basis for remaining subjects.
Question 7: What distinguishes a Data Protection Impact Assessment (DPIA) tracking tool from a general risk register in a GDPR context?
- DPIAs are voluntary; risk registers are mandatory
- DPIA tools focus specifically on high-risk processing as required by Article 35 (Correct answer)
- Risk registers replace the need for DPIAs
- DPIA tools only apply to processors, not controllers
Correct answer: DPIA tools focus specifically on high-risk processing as required by Article 35
DPIA tracking tools are scoped to the Article 35 obligation — identifying and managing high-risk processing operations before they begin.
Under GDPR, which document produced by a monitoring tool serves as primary evidence during a supervisory authority inspection of processing activities?