GDPR Specialist Principles and Concepts 2 — Questions and Answers
Question 1: Under GDPR, what is the maximum timeframe for notifying a supervisory authority after discovering a personal data breach that poses a risk to individuals?
- 24 hours
- 48 hours
- 72 hours (Correct answer)
- 7 days
Correct answer: 72 hours
Article 33 requires notification to the supervisory authority within 72 hours of becoming aware of a personal data breach, where feasible.
Question 2: Which GDPR principle requires that personal data be collected only for specified, explicit, and legitimate purposes and not further processed in a manner incompatible with those purposes?
- Data minimisation
- Purpose limitation (Correct answer)
- Storage limitation
- Integrity and confidentiality
Correct answer: Purpose limitation
The purpose limitation principle in Article 5(1)(b) restricts the use of personal data to the specific purposes for which it was originally collected.
Question 3: A company transfers EU resident data to a US-based cloud provider. Under GDPR, which mechanism could NOT independently serve as a valid transfer safeguard after Schrems II?
- Standard Contractual Clauses with a Transfer Impact Assessment
- Binding Corporate Rules
- EU-US Privacy Shield (Correct answer)
- Adequacy decision for the EU-US Data Privacy Framework
Correct answer: EU-US Privacy Shield
The Court of Justice of the EU invalidated the Privacy Shield in the Schrems II ruling (C-311/18, 2020), making it no longer a valid transfer mechanism.
Question 4: Under GDPR's accountability principle, which document must a controller with 250 or more employees maintain?
- Data Protection Impact Assessment
- Records of Processing Activities (Correct answer)
- Data Breach Register
- Privacy Notice
Correct answer: Records of Processing Activities
Article 30 requires controllers with 250+ employees (and those meeting other thresholds) to maintain Records of Processing Activities (RoPA).
Question 5: What distinguishes 'pseudonymisation' from 'anonymisation' under GDPR?
- Pseudonymised data is fully outside GDPR scope; anonymised data is not
- Pseudonymised data can be re-identified with additional information; anonymised data cannot (Correct answer)
- Anonymisation requires encryption; pseudonymisation does not
- They are legally equivalent terms under GDPR
Correct answer: Pseudonymised data can be re-identified with additional information; anonymised data cannot
Pseudonymised data still allows re-identification using separately held additional information, so it remains personal data under GDPR, while truly anonymised data does not.
Question 6: Which GDPR provision specifically addresses automated individual decision-making, including profiling, that produces significant legal or similarly significant effects?
- Article 17
- Article 20
- Article 22 (Correct answer)
- Article 25
Correct answer: Article 22
Article 22 gives data subjects the right not to be subject to solely automated decisions that significantly affect them, with limited exceptions.
Question 7: A data processor discovers a security incident affecting client data. Under GDPR, what is the processor's FIRST obligation?
- Notify affected data subjects directly
- Notify the relevant supervisory authority within 72 hours
- Notify the data controller without undue delay (Correct answer)
- Conduct a Data Protection Impact Assessment
Correct answer: Notify the data controller without undue delay
Article 33(2) requires processors to notify their controller without undue delay after becoming aware of a personal data breach, leaving supervisory notification to the controller.
Under GDPR, what is the maximum timeframe for notifying a supervisory authority after discovering a personal data breach that poses a risk to individuals?