GDPR Specialist Compliance and Enforcement 2 — Questions and Answers
Question 1: Under GDPR Article 83, what is the maximum administrative fine for a violation of the basic principles for processing personal data?
- €10 million or 2% of global annual turnover
- €20 million or 4% of global annual turnover (Correct answer)
- €5 million or 1% of global annual turnover
- €50 million or 10% of global annual turnover
Correct answer: €20 million or 4% of global annual turnover
Violations of basic processing principles (Articles 5, 6, 7, 9) carry the highest tier fine: €20 million or 4% of total worldwide annual turnover, whichever is higher.
Question 2: A supervisory authority receives a complaint against a controller established in multiple EU Member States. Which authority has lead supervisory authority competence?
- The authority where the complainant resides
- The authority where the controller has its main establishment (Correct answer)
- Any authority can claim jurisdiction
- The European Data Protection Board decides
Correct answer: The authority where the controller has its main establishment
The lead supervisory authority is the authority in the Member State where the controller's main establishment is located, per GDPR Article 56.
Question 3: What must a controller demonstrate to prove compliance under GDPR's accountability principle?
- Only that a DPO has been appointed
- That data subjects have been informed via a privacy notice
- That appropriate technical and organizational measures have been implemented and documented (Correct answer)
- That all processing is based on consent
Correct answer: That appropriate technical and organizational measures have been implemented and documented
Article 5(2) requires controllers to be able to demonstrate compliance through documented technical and organizational measures.
Question 4: An organization transfers personal data to a US-based processor. The processor has undergone an EU Standard Contractual Clause (SCC) agreement. What additional step is required post-Schrems II?
- No additional steps are needed if SCCs are signed
- Obtain a Binding Corporate Rule approval
- Conduct a Transfer Impact Assessment (TIA) (Correct answer)
- File notification with the lead supervisory authority
Correct answer: Conduct a Transfer Impact Assessment (TIA)
Following the Schrems II ruling, organizations must conduct a Transfer Impact Assessment to evaluate whether the destination country's law undermines the SCC protections.
Question 5: Under GDPR, which enforcement tool allows a supervisory authority to temporarily or permanently ban processing?
- Corrective power under Article 58(2)(f) (Correct answer)
- Investigative power under Article 58(1)
- Advisory power under Article 58(3)
- Judicial remedy under Article 78
Correct answer: Corrective power under Article 58(2)(f)
Article 58(2)(f) grants supervisory authorities the corrective power to impose a temporary or permanent ban on processing.
Question 6: A DPO discovers that the organization's cookie consent mechanism does not allow users to withdraw consent as easily as they gave it. Which GDPR requirement is violated?
- Article 13 — transparency obligation
- Article 7(3) — right to withdraw consent (Correct answer)
- Article 25 — data protection by design
- Article 32 — security of processing
Correct answer: Article 7(3) — right to withdraw consent
Article 7(3) explicitly requires that withdrawing consent must be as easy as giving it, and failure to ensure this invalidates consent as a lawful basis.
Question 7: When must a controller notify the supervisory authority of a personal data breach?
- Within 24 hours of becoming aware
- Without undue delay and within 72 hours of becoming aware (Correct answer)
- Within 30 days of detection
- Only if the breach affects more than 1,000 individuals
Correct answer: Without undue delay and within 72 hours of becoming aware
Article 33 requires controllers to notify the competent supervisory authority without undue delay and, where feasible, not later than 72 hours after becoming aware of the breach.
Under GDPR Article 83, what is the maximum administrative fine for a violation of the basic principles for processing personal data?