A person buys a product at a store located in the European Economic Area (EEA). At the time of purchase, you are asked to fill out a registration form and he informs his personal email.
As is usual in many stores, in the next few days this person will start receiving several marketing emails. He considers the frequency of these emails to be very high. Demanding his rights, he asks the store to delete all his personal data.
What the store must do according to the General Data Protection Regulation (GDPR)?
Data protection and privacy are closely related terms. Which of these options best represent this relationship?
Important technical requirements set out in the General Data Protection Regulation (GDPR) are about data quality. One is the obligation to ensure appropriate security, including protection against unauthorized or unlawful processing.
What is another important technical requirement?
The GDPR states that records of processing activities must be kept by the controller. To whom must the controller make these records available, if requested?
Which of these should appear in a Data Protection Impact Assessment (DPIA) according to the General Data Protection Regulation (GDPR)?
According to the principle of purpose limitation, data should not be processed beyond the legitimate purpose defined. However, further processing is allowed in a few specific cases, provided that appropriate safeguards for the rights and freedoms of the data subjects are taken. For which purpose is further processing not allowed?
A company is planning to process personal data. The recently appointed data protection officer (DPO) executes a data protection impact assessment (DPIA). The DPO finds that all computers have a setting causing monitors to show a screen saver after five seconds of inaction. However, the computers are not locked automatically. When employees leave their desk, they usually do not lock their computers either. What is this an example of?
The General Data Protection Regulation (GDPR) in its Article 30 legislates on the Records of treatment activities.
If requested, the controller must provide these records:
Which of the following has a data breach under the General Data Protection Regulation (GDPR)?
Which organizations need to comply with the General Data Protection Regulation (GDPR)?
A gentleman has a loan denied by the bank’s system that he has been a customer for many years. He is disgusted, because the loan would make it possible to hold the wedding of his only granddaughter.
He contacts the bank and asks for explanations. He wants to know exactly why his loan was denied and based on what information.
What right is required by the data subject according to the GDPR?
The word privacy is never mentioned in the General Data Protection Regulation (GDPR) text.
Despite this, what would be the best definition of the privacy according to the Regulation?
The General Data Protection Regulation (GDPR) is based on the principles of proportionality and subsidiarity.
What is the meaning of “proportionality” in this context?
GDPR quotes in one of its principles that personal data should be adequate, relevant and limited to what is necessary in relation to its purpose. What principle is this?
What is the term used in the General Data Protection Regulation (GDPR) for the disclosure of, or unauthorized access to, personal data?