RGPD Flashcards
revision (56 cards)
What does GDPR stand for?
General Data Protection Regulation
True or False: GDPR applies only to organizations within the EU.
False
What is the primary purpose of the GDPR?
To protect the privacy and personal data of individuals.
Fill in the blank: GDPR came into effect on _________.
May 25, 2018
What is considered personal data under GDPR?
Any information relating to an identified or identifiable natural person.
Which article of GDPR outlines the principles of data processing?
Article 5
True or False: Data subjects have the right to access their personal data.
True
What is the maximum fine for non-compliance with GDPR?
Up to 20 million euros or 4% of global annual turnover, whichever is higher.
What does the term ‘data processor’ refer to in GDPR?
A person or entity that processes data on behalf of the data controller.
What is required for lawful processing of personal data under GDPR?
One of the six legal bases outlined in Article 6.
Which article grants individuals the right to erasure?
Article 17
True or False: GDPR requires data breaches to be reported within 72 hours.
True
What does DPIA stand for?
Data Protection Impact Assessment
Fill in the blank: The GDPR applies to ________ processing of personal data.
automated and manual
What is a data protection officer (DPO)?
An individual appointed to oversee data protection strategies and ensure compliance.
True or False: Consent must be explicit and revocable under GDPR.
True
What does Article 32 of GDPR address?
Security of processing
What rights do data subjects have under GDPR?
Right to access, right to rectification, right to erasure, right to restrict processing, right to data portability, right to object.
What is the role of the European Data Protection Board (EDPB)?
To ensure consistent application of GDPR across EU member states.
Which law complements GDPR in France?
Loi Informatique et Libertés
True or False: Personal data can be processed without consent if it is necessary for the performance of a contract.
True
What is the main goal of data minimization as per GDPR?
To ensure only necessary data is processed.
What is the ‘right to data portability’?
The right for individuals to obtain and reuse their personal data across different services.
Fill in the blank: Under GDPR, data processing must be ________ and _________.
lawful; transparent