매달, 우리는 1000명 이상의 사람들이 시험 준비를 잘하고 시험을 잘 통과할 수 있도록 도와줍니다.
  / PDPF 덤프  / PDPF 문제 연습


Privacy and Data Protection Foundation Exam 온라인 연습

최종 업데이트 시간: 2025년02월25일

당신은 온라인 연습 문제를 통해 EXIN PDPF 시험지식에 대해 자신이 어떻게 알고 있는지 파악한 후 시험 참가 신청 여부를 결정할 수 있다.

시험을 100% 합격하고 시험 준비 시간을 35% 절약하기를 바라며 PDPF 덤프 (최신 실제 시험 문제)를 사용 선택하여 현재 최신 149개의 시험 문제와 답을 포함하십시오.

 / 4

Question No : 1

Which of the following types of transfers of personal data outside the European Economic Area (EEA) is allowed?

Compulsory Corporate Rules are rules used internally by multinational companies to transfer personal data. Thus, it is possible to transfer data between them, even if the destination company is in a country that does not have an adequate level of data protection. These rules are like an internal corporate code of conduct and do not cover transfers of personal data outside the corporate group.
Do not confuse "Compulsory Corporate Rules" with "Standard Contractual Clauses". The last are clauses in contracts for international data transfer between companies (customer and supplier relationship) where the destination country does not have an adequate level of data protection, and depends on authorization from the Supervisory Authority.
Article 58 of GDPR

Question No : 2

Which of the following options describes the concept of data minimization?

In its Article 5, which deals with the Principles relating to the processing of personal data, paragraph 1, the GDPR describes:

Question No : 3

What is the main objective of the “Lifecycle Protection” principle?

Data Life Cycle Management (DLM)
It aims to manage data flow throughout the lifecycle, from collection, processing, sharing, storage and deletion.
Having the knowledge where the data travels, who is responsible, who has access, helps a lot to implement security measures.

Question No : 4

After appearing in a photo posted by a friend on a social network, a person felt embarrassed and decided that he wants the photo to be deleted.
According to the General Data Protection Regulation (GDPR), does that person have the right to delete this photo?

GDPR does not apply to the use of personal data for domestic purposes, however in this example the controller is the Social Network, as it performs the processing of the photos. Therefore, the owner has the right to delete this photo.
For domestic purposes, data collection is not intended for professional or commercial purposes. Examples are the get-togethers of friends and family where we can collect names, phone numbers, e-mails to facilitate the organization, as well as taking pictures to record the moment. Now if you have a blog where you can record several moments with your friends and you monetize it in some way C watch out! C you are under the scope of GDPR.
Whereas Recital 18: “This Regulation does not apply to the processing of personal data by a naturalperson in the course of a purely personal or household activity and thus with no connection to aprofessional or commercial activity. Personal or household activities could include correspondence and the holding of addresses, or social networking and online activity undertaken within the context of such activities.
However, this Regulation applies to controllers or processors which provide the means for processingpersonal data for such personal or household activities.”

Question No : 5

Which of the parts below can implement data protection by design (from conception)?

It is the duty of the processor to guarantee security in the treatment of the data entrusted to it by the controller.

Question No : 6

In the contract between the controller and processor for the processing of personal data, which of the options below represents the sole responsibility of the Controller?

The correct option is exclusively for the Controller, the others are for the Processor in accordance with Articles 25 and 28 of the GDPR.

Question No : 7

Which organizations need to comply with the General Data Protection Regulation (GDPR)?

This is a question that has the most doubts: “Who needs to adapt?". For example: 1 - If you have a company in Brazil and sell products or services and process personal data from residents in the EU, in this case your company must conform to the GDPR. 2- If you have a company located in the EU and handle personal data.
Transcribing here part of Article 3 of the GDPR:

Question No : 8

A company is planning to process personal data. The recently appointed data protection officer (DPO) executes a data protection impact assessment (DPIA). The DPO finds that all computers have a setting causing monitors to show a screen saver after five seconds of inaction.
However, the computers are not locked automatically. When employees leave their desk, they usually do not lock their computers either.
What is this an example of?

Data access. Incorrect. The data have not been accessed.
Personal data breach. Incorrect. No personal data has been processed unauthorized yet, so it is not a breach.
Security incident. Incorrect. Processing has yet to begin, there is no reason to assume an incident has taken place.
Security vulnerability. Correct. Confidentiality of the data cannot be guaranteed if employees leave their workstation without locking the computer. (Literature: A, Chapter 2; GDPR Article 5(1)(f))

Question No : 9

GDPR quotes in one of its principles that personal data should be adequate, relevant and limited to what is necessary in relation to its purpose.
What principle is this?

In its Article 5, which deals with the Principles concerning the processing of personal data, paragraph 1, the GDPR describes:

Question No : 10

The General Data Protection Regulation (GDPR) came into effect on May 25, 2018, what is the legal status of this regulation?

When we have a Regulation, such as the GDPR, all EU member states are obliged to follow it. The regulation is a law and Member States cannot create laws that oppose it. Unlike the Directives that set objectives to be achieved, however, each Member State is free to decide how to apply them in its country.

Question No : 11

A written contract between a controller and a processor is called a data processing agreement.
According to the GDPR, what does not have to be covered in the written contract?

The contractor code of business ethics and conduct that is used. Correct. Although the GDPR endorses the use of codes of conduct and certification, it is not an obligation to have this clause to demonstrate compliance with the GDPR. (Literature: A, Chapter 8; GDPR Article 28(3))
The information security and personal data breach procedures. Incorrect. This is mandatory because it describes the obligations of the processor regarding the notification of a personal data breach (by the controller) to the supervisory authority.
The technical and organizational measures implemented. Incorrect. This is mandatory because it describes technical and organizational measures the processor must take.
Which data are covered by the data processing agreement. Incorrect. This is mandatory because it describes the personal data, including special category personal data, covered by the contract.

Question No : 12

What does the GDPR concept of ‘binding corporate rules’ (BCR) imply?


Question No : 13

The General Data Protection Regulation (GDPR) allows processing of personal data only for purposes explicitly permitted by law. A tax advisor wants to file income tax returns for a neighbor.
Which of the legitimate grounds in the GDPR applies?


Question No : 14

Personal data can be transferred outside of the EEA. According to the GDPR, which transfers outside the EEA are always lawful?
A. Transfers based on the laws of the non-EEA country concerns
B. Transfers falling under World Trade Organization rules
C. Transfers governed by approved binding corporate rules (BCR)
D. Transfers within a global corporation or organization

정답: C
Transfers based on the laws of the non-EEA country concerned. Incorrect. This would also require an adequacy decision confirming that those laws are sufficient.
Transfers falling under World Trade Organization rules. Incorrect. WTO only covers free trade of goods and services.
Transfers governed by approved binding corporate rules (BCR). Correct. Binding corporate rules approved by a supervisory authority involved make the transfer lawful. (Literature: A, Chapter 7; GDPR Article 47)
Transfers within a global corporation or organization. Incorrect. This would also require that they adopt official binding corporate rules.
Reference: https://edps.europa.eu/data-protection/data-protection/reference-library/international-transfers_en

Question No : 15

What should be done by the EU member states and is not a responsibility of the supervisory authorities?


 / 4