GDPR 2018 Flashcards
What does GDPR stand for?
General Data Protection Regulation
True or False: GDPR applies only to organizations within the European Union.
False
What is the primary purpose of GDPR?
To protect the privacy and personal data of individuals within the EU.
Fill in the blank: GDPR came into effect on _______.
May 25, 2018
Which of the following is a key principle of GDPR? (a) Data Minimization (b) Data Maximization
a) Data Minimization
What rights do individuals have under GDPR?
Rights include access, rectification, erasure, restriction of processing, data portability, and the right to object.
True or False: Organizations must appoint a Data Protection Officer (DPO) under GDPR.
True
What is ‘personal data’ as defined by GDPR?
Any information relating to an identified or identifiable natural person.
What is the maximum fine for non-compliance with GDPR?
Up to €20 million or 4% of global annual turnover, whichever is higher.
What is the ‘Right to be Forgotten’?
The right of individuals to have their personal data erased under certain conditions.
Fill in the blank: GDPR requires organizations to report data breaches within _______ hours.
72
Which of the following is NOT considered personal data? (a) Name (b) Company name
b) Company name
What is ‘data portability’ under GDPR?
The right of individuals to obtain and reuse their personal data across different services.
True or False: Consent under GDPR must be explicit and informed.
True
What does ‘privacy by design’ mean in the context of GDPR?
Incorporating data protection measures from the start of any project or system.
What is a Data Processing Agreement (DPA)?
A contract between a data controller and a data processor that outlines the processing of personal data.
Fill in the blank: GDPR applies to _______ data processors and controllers.
all
What does ‘legitimate interest’ mean in GDPR?
A lawful basis for processing personal data where the processing is necessary for the legitimate interests of the data controller.
Which authority oversees the enforcement of GDPR?
Data Protection Authorities (DPAs) in each EU member state.
True or False: GDPR allows for the transfer of personal data outside the EU.
True
What is ‘profiling’ in the context of GDPR?
Any form of automated processing of personal data to evaluate certain personal aspects of an individual.
Fill in the blank: GDPR was designed to replace the _______ directive.
Data Protection
What is the significance of ‘Article 30’ in GDPR?
It requires organizations to maintain a record of processing activities.
What does the term ‘data breach’ mean?
A security incident that results in unauthorized access to personal data.