GDPR Security & Access Management 3 — Questions and Answers
Question 1: A healthcare organisation transfers patient records to a cloud provider. Under GDPR, which contractual clause is MANDATORY regarding security?
- The processor must obtain cyber insurance coverage
- The processor must process data only on controller instructions and implement Article 32 security measures (Correct answer)
- The processor must store data exclusively within the EU
- The processor must achieve ISO 27001 certification
Correct answer: The processor must process data only on controller instructions and implement Article 32 security measures
Article 28(3) mandates that processor agreements include requirements to follow controller instructions and implement appropriate security under Article 32.
Question 2: What does 'privacy by default' require specifically regarding access to personal data systems?
- All users must complete GDPR training before accessing any system
- Systems must default to the most privacy-protective settings, limiting access to what is necessary (Correct answer)
- Personal data must be encrypted by default for all users
- Access logs must be reviewed weekly by the DPO
Correct answer: Systems must default to the most privacy-protective settings, limiting access to what is necessary
Article 25(2) requires that by default, only personal data necessary for each specific purpose is processed, including limiting access scope.
Question 3: An attacker gains access to a database by exploiting an unpatched vulnerability and exfiltrates 50,000 customer records. Under GDPR, what is the maximum administrative fine the controller could face?
- €10 million or 2% of global annual turnover, whichever is higher
- €20 million or 4% of global annual turnover, whichever is higher (Correct answer)
- €5 million or 1% of global annual turnover, whichever is higher
- €50 million regardless of turnover
Correct answer: €20 million or 4% of global annual turnover, whichever is higher
Failure to implement appropriate security under Article 32 falls under Article 83(4), but serious breaches of core principles can reach €20M/4% under Article 83(5).
Question 4: Which access management approach aligns best with GDPR's principle of data minimisation for system administrators?
- Granting admins full unrestricted access to all systems for operational efficiency
- Providing admins access only to the specific systems and data required for their duties (Correct answer)
- Requiring admin approval for all data access requests across the organisation
- Rotating admin credentials monthly regardless of access scope
Correct answer: Providing admins access only to the specific systems and data required for their duties
Least-privilege access for administrators ensures they can only access what is necessary for their role, directly implementing data minimisation.
Question 5: Under GDPR, a data breach notification to the supervisory authority must be made within what timeframe after the controller becomes aware of it?
- 24 hours
- 48 hours
- 72 hours (Correct answer)
- 7 days
Correct answer: 72 hours
Article 33(1) requires notification to the supervisory authority within 72 hours of the controller becoming aware of the breach, where feasible.
Question 6: A company uses a shared login account ('admin123') that multiple employees use to access a database containing personal data. Which specific GDPR requirement does this violate?
- The requirement to appoint a Data Protection Officer
- The requirement for appropriate technical measures including individual accountability (Correct answer)
- The requirement to maintain a Record of Processing Activities
- The requirement to conduct a Data Protection Impact Assessment
Correct answer: The requirement for appropriate technical measures including individual accountability
Shared accounts prevent individual accountability in access logs, violating Article 32's requirement for appropriate technical security measures.
Question 7: When must a controller notify data subjects about a personal data breach under GDPR Article 34?
- Always, within 72 hours of discovering the breach
- When the breach is likely to result in a high risk to the rights and freedoms of individuals (Correct answer)
- Only when financial data is compromised
- When more than 1,000 individuals are affected by the breach
Correct answer: When the breach is likely to result in a high risk to the rights and freedoms of individuals
Article 34 requires notifying affected individuals only when the breach is likely to result in a high risk to their rights and freedoms — not all breaches require individual notification.
A healthcare organisation transfers patient records to a cloud provider.
Under GDPR, which contractual clause is MANDATORY regarding security?