GDPR Specialist Principles and Concepts 3 — Questions and Answers
Question 1: Under GDPR, when is a Data Protection Impact Assessment (DPIA) mandatory?
- For all processing of personal data regardless of risk
- When processing is likely to result in a high risk to the rights and freedoms of natural persons (Correct answer)
- Only when processing special category data
- Whenever a Data Protection Officer is appointed
Correct answer: When processing is likely to result in a high risk to the rights and freedoms of natural persons
Article 35 mandates a DPIA when processing is likely to result in a high risk to individuals' rights and freedoms, particularly for new technologies or large-scale profiling.
Question 2: Which of the following organizations is NOT required to designate a Data Protection Officer (DPO) under Article 37 GDPR?
- A public authority processing citizen data
- A company whose core activities involve large-scale systematic monitoring of individuals
- A small retailer processing employee payroll data only (Correct answer)
- An organization processing special category data on a large scale
Correct answer: A small retailer processing employee payroll data only
A small retailer processing employee payroll incidentally does not meet the Article 37 thresholds (public authority, large-scale monitoring, or large-scale special category processing).
Question 3: GDPR's 'right to erasure' (Article 17) is absolute in all circumstances.
- True — individuals can always demand deletion of their data
- False — it is subject to exceptions including legal obligations and public interest tasks (Correct answer)
- True — but only for special category data
- False — it only applies to data collected under consent
Correct answer: False — it is subject to exceptions including legal obligations and public interest tasks
Article 17 provides the right to erasure but includes exceptions for legal obligations, public interest, archiving purposes, and legal claims.
Question 4: A controller relies on 'legitimate interests' as the lawful basis for processing. What additional balancing test must be satisfied?
- The processing must be necessary for contract performance
- The legitimate interest must not be overridden by the data subject's interests or rights (Correct answer)
- Explicit consent must also be obtained
- The DPO must approve each processing activity
Correct answer: The legitimate interest must not be overridden by the data subject's interests or rights
Article 6(1)(f) requires that the controller's legitimate interests are not overridden by the interests, rights, or freedoms of the data subject — the three-part LIA test.
Question 5: What is the role of the 'lead supervisory authority' under GDPR's One-Stop-Shop mechanism?
- It is the supervisory authority in any EU member state where a complaint is filed
- It is the supervisory authority of the member state where the controller has its main establishment (Correct answer)
- It supervises all processors regardless of location
- It is appointed by the European Data Protection Board
Correct answer: It is the supervisory authority of the member state where the controller has its main establishment
The lead supervisory authority is determined by the location of the controller's or processor's main establishment, serving as the primary regulatory contact for cross-border processing.
Question 6: Under GDPR, 'special categories of personal data' require a stricter lawful basis. Which of the following is NOT classified as a special category?
- Genetic data
- Financial data (e.g., credit card numbers) (Correct answer)
- Biometric data used for identification
- Data revealing religious beliefs
Correct answer: Financial data (e.g., credit card numbers)
Article 9 lists special categories including health, racial/ethnic origin, religion, genetic/biometric, sexual orientation, and political opinions — financial data is not included.
Question 7: Which GDPR principle mandates that personal data must be kept in a form that permits identification for no longer than necessary?
- Data minimisation
- Accuracy
- Storage limitation (Correct answer)
- Purpose limitation
Correct answer: Storage limitation
The storage limitation principle in Article 5(1)(e) requires that personal data be retained only as long as necessary for the specified purpose.
Under GDPR, when is a Data Protection Impact Assessment (DPIA) mandatory?