GDPR Security & Access Management 2 — Questions and Answers
Question 1: Under GDPR Article 32, which factor does NOT need to be considered when implementing appropriate technical security measures?
- The cost of implementation
- The nature and context of processing
- The profitability of the data controller (Correct answer)
- The risks to rights and freedoms of individuals
Correct answer: The profitability of the data controller
Article 32 requires considering costs, nature/context, and risks — but profitability of the controller is not a relevant factor.
Question 2: A company implements role-based access control (RBAC) so employees only access personal data needed for their job. Which GDPR principle does this primarily support?
- Storage limitation
- Data minimisation (Correct answer)
- Purpose limitation
- Accuracy
Correct answer: Data minimisation
RBAC limiting access to only necessary data is a technical implementation of the data minimisation principle (Article 5(1)(c)).
Question 3: What is the primary purpose of implementing pseudonymisation as a security measure under GDPR?
- To permanently remove identifying information from datasets
- To replace identifying fields with artificial identifiers, reducing risk while retaining utility (Correct answer)
- To encrypt all personal data at rest and in transit
- To anonymise data so it falls outside GDPR scope
Correct answer: To replace identifying fields with artificial identifiers, reducing risk while retaining utility
Pseudonymisation replaces direct identifiers with artificial ones, reducing exposure risk while keeping data useful — it is still personal data under GDPR.
Question 4: Which scenario best demonstrates the principle of 'integrity and confidentiality' under GDPR Article 5(1)(f)?
- Deleting personal data after its retention period expires
- Using encryption and access controls to prevent unauthorised processing (Correct answer)
- Correcting inaccurate personal data upon request
- Notifying individuals of how their data is used
Correct answer: Using encryption and access controls to prevent unauthorised processing
Article 5(1)(f) requires processing personal data in a manner ensuring appropriate security, including protection against unauthorised access — achieved via encryption and access controls.
Question 5: An organisation discovers that a former employee's credentials were used to access personal data after their contract ended. Which access management failure does this represent?
- Insufficient encryption standards
- Failure to implement multi-factor authentication
- Inadequate offboarding and access revocation procedures (Correct answer)
- Lack of data loss prevention (DLP) tools
Correct answer: Inadequate offboarding and access revocation procedures
Using terminated employee credentials indicates the organisation failed to revoke access during offboarding, a fundamental access lifecycle management failure.
Question 6: Under GDPR, when a processor implements security measures, who bears ultimate responsibility for ensuring those measures are appropriate?
- The processor alone, as they control the infrastructure
- The supervisory authority, which sets minimum standards
- The controller, who must ensure processor compliance via contract (Correct answer)
- Both share equal responsibility with no primary party
Correct answer: The controller, who must ensure processor compliance via contract
Under Article 28, controllers must only use processors providing sufficient guarantees and must contractually require appropriate security measures.
Question 7: A GDPR-compliant access control policy requires audit logs of who accessed personal data and when. Which security concept does this primarily address?
- Availability
- Integrity
- Accountability (Correct answer)
- Confidentiality
Correct answer: Accountability
Audit logs of access events support accountability — enabling organisations to demonstrate compliance and trace unauthorised access.
Under GDPR Article 32, which factor does NOT need to be considered when implementing appropriate technical security measures?