PECB certification preparation

GDPR Practice Questions

Practice exam-style questions, check your answers, and review explanations and source references where they are available.

Exam
GDPR
Provider
PECB
Full set
80 questions
Last Update Check

Navigating the complexities of data privacy requires top-tier resources, and we at Cert Mage are here to guide you through your GDPR certification. We have meticulously crafted a targeted GDPR question bank that covers all critical compliance frameworks and regulatory requirements. Our interactive exam simulator provides a realistic testing environment to help you manage your time effectively. Start by exploring our free GDPR sample questions to establish your baseline understanding. When you feel ready, our extensive library of GDPR practice questions and actual exam questions will ensure you walk into the testing center fully prepared.

Questio n: What is the role of the DPO in a DPIA?
Answer options
Scenario: A clinical research organization collects and processes sensitive personal data of individuals for medical research purposes. The data is encrypted and stored in a central database using a one-way hashing function (bcrypt). The organization conducted a risk assessment to identify and mitigate risks. Questio n: Should a DPIA be conducted in this case?
Answer options
Which statement below regarding the difference between anonymization and pseudonymization is correct?
Answer options
Bus Spot is one of the largest bus operators in Spain. The company operates in local transport and bus rental since 2009. The success of Bus Spot can be attributed to the digitization of the bus ticketing system, through which clients can easily book tickets and stay up to date on any changes to their arrival or departure time. In recent years, due to the large number of passengers transported daily. Bus Spot has dealt with different incidents including vandalism, assaults on staff, and fraudulent injury claims. Considering the severity of these incidents, the need for having strong security measures had become crucial. Last month, the company decided to install a CCTV system across its network of buses. This security measure was taken to monitor the behavior of the company's employees and passengers, enabling crime prevention and ensuring safety and security. Following this decision, Bus Spot initiated a data protection impact assessment (DPIA). The outcome of each step of the DPIA was documented as follows: Step 1: In all 150 buses, two CCTV cameras will be installed. Only individuals authorized by Bus Spot will have access to the information generated by the CCTV system. CCTV cameras capture images only when the Bus Spot's buses are being used. The CCTV cameras will record images and sound. The information is transmitted to a video recorder and stored for 20 days. In case of incidents, CCTV recordings may be stored for more than 40 days and disclosed to a law enforcement body. Data collected through the CCTV system will be processed bv another organization. The purpose of processing this tvoe of information is to increase the security and safety of individuals and prevent criminal activity. Step 2: All employees of Bus Spot were informed for the installation of a CCTV system. As the data controller, Bus Spot will have the ultimate responsibility to conduct the DPI
Answer options
Questio n: Under GDPR, the controller must demonstrate that data subjects have consented to the processing of their personal data, and the consent must be freely given. What is the role of the DPO in ensuring compliance with this requirement?
Answer options
Scenario 1: MED is a healthcare provider located in Norway. It provides high-quality and affordable healthcare services, including disease prevention, diagnosis, and treatment. Founded in 1995, MED is one of the largest health organizations in the private sector. The company has constantly evolved in response to patients' needs. Patients that schedule an appointment in MED's medical centers initially need to provide their personal information, including name, surname, address, phone number, and date of birth. Further checkups or admission require additional information, including previous medical history and genetic dat a. When providing their personal data, patients are informed that the data is used for personalizing treatments and improving communication with MED's doctors. Medical data of patients, including children, are stored in the database of MED's health information system. MED allows patients who are at least 16 years old to use the system and provide their personal information independently. For children below the age of 16, MED requires consent from the holder of parental responsibility before processing their data. MED uses a cloud-based application that allows patients and doctors to upload and access information. Patients can save all personal medical data, including test results, doctor visits, diagnosis history, and medicine prescriptions, as well as review and track them at any time. Doctors, on the other hand, can access their patients' data through the application and can add information as needed. Patients who decide to continue their treatment at another health institution can request MED to transfer their data. However, even if patients decide to continue their treatment elsewhere, their personal data is still used by MED. Patients’ requests to stop data processing are rejected. This decision was made by MED’s top management to retain the information of everyone registered in their databases. The company also shares medical data with InsHealth, a health insurance company. MED's data helps InsHealth create health insurance plans that meet the needs of individuals and families. MED believes that it is its responsibility to ensure the security and accuracy of patients’ personal data. Based on the identified risks associated with data processing activities, MED has implemented appropriate security measures to ensure that data is securely stored and processed. Since personal data of patients is stored and transmitted over the internet, MED uses encryption to avoid unauthorized processing, accidental loss, or destruction of data. The company has established a security policy to define the levels of protection required for each type of information and processing activity. MED has communicated the policy and other procedures to personnel and provided customized training to ensure proper handling of data processing. Questio n: Considering the nature of data processing activities described in scenario 1, is GDPR applicable to MED?
Answer options
Scenario: PickFood is an online food delivery service that allows customers to order food online and pay by credit card. The payment service is provided by PaySmart, which processes the transactions. Questio n: According to Article 30 of GDPR, what type of information should PaySmart NOT maintain when recording online transaction processing activity?
Answer options
An organization suffered a personal data breach. The attackers gained access to their database through a user account that had unlimited access to dat a. What should the DPO advise the organization to do in order to prevent the recurrence of similar scenarios?
Answer options
Why should the controller implement appropriate technical and organizational measures?
Answer options
Scenario: An organization has been using a storage transfer service to import market-sensitive data, including email addresses and contact details, into a cloud storage system. This change has affected the registration process and has helped the organization appropriately collect and store data. Questio n: Based on this scenario, what should the DPO monitor in the data processing register?
Answer options
Question 1 of 10

Source context

How this practice set is maintained

Maintained by the CertMage content team, this page loads questions from the exam dataset connected to its preparation resource. When an answer includes a supporting reference, it is shown with that answer so you can review the underlying vendor documentation.

Certification objectives, interfaces, and vendor services can change. Verify important details against the provider's current exam guide and documentation before your exam.

Scroll to Top