Test Questions Flashcards
When does an organization need to take action to legitimize cross-border transfers?
when data transferred from a jurisdiction in the EU to a 3rd country not adequate
What is the time period within which a controller needs to respond to a data subject request?
without undue delay or within one month of receiving request
As a regulation, are GDPR’s provisions binding?
Yes.
on EU member states but leaves discretion in some areas
When processing an individual’s personal data in the context of direct marketing activities, what must data controllers do?
provide individuals with information explaining that their personal data will be used for marketing purposes
Can you require consent?
No.
consent must be freely given - given on a voluntary basis. there must be a real choice. any element of inappropriate pressure or influence renders the consent invalid.
What information should be provided in an employer notice about monitoring?
purpose of monitoring
potential uses of the data
employee rights related to their data
whom employees should contact
What must a controller do upon receiving a proper request for erasure and that data has been made public?
take reasonable steps, including technical measures, to inform controllers which are processing the personal data that the data subject has requested the erasure by such controllers of any links to, or copy or replication of, those personal data.
What was a major goal of the OECD Guidelines, Convention 108 and Data Protection Directive?
synchronization of approaches to data protection
(harmonized approach)
What are the 7 Privacy Shield principles?
- Notice
- Access
- Choice
- Accountability for onward transfer
- Security
- Data integrity and purpose limitation
- Recourse, enforcement and liability
How is pseudyonmous data defined in GDPR?
Data that cannot be attributed to a specific data subject without the use of additional
information kept separately.
When does the right not to be subject to automated decision-making NOT apply?
- decision is necessary for entering into or performance of a contract
- authorized by Union or Member State law, and tehre are suitable safeguards
- based on data subject’s explicit consent
Can a data subject lodge a complaint with SA without first registering complaint with controller?
Yes.