RGPD Flashcards

revision (56 cards)

1
Q

What does GDPR stand for?

A

General Data Protection Regulation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

True or False: GDPR applies only to organizations within the EU.

A

False

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is the primary purpose of the GDPR?

A

To protect the privacy and personal data of individuals.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Fill in the blank: GDPR came into effect on _________.

A

May 25, 2018

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is considered personal data under GDPR?

A

Any information relating to an identified or identifiable natural person.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Which article of GDPR outlines the principles of data processing?

A

Article 5

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

True or False: Data subjects have the right to access their personal data.

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is the maximum fine for non-compliance with GDPR?

A

Up to 20 million euros or 4% of global annual turnover, whichever is higher.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What does the term ‘data processor’ refer to in GDPR?

A

A person or entity that processes data on behalf of the data controller.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is required for lawful processing of personal data under GDPR?

A

One of the six legal bases outlined in Article 6.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Which article grants individuals the right to erasure?

A

Article 17

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

True or False: GDPR requires data breaches to be reported within 72 hours.

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What does DPIA stand for?

A

Data Protection Impact Assessment

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Fill in the blank: The GDPR applies to ________ processing of personal data.

A

automated and manual

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is a data protection officer (DPO)?

A

An individual appointed to oversee data protection strategies and ensure compliance.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

True or False: Consent must be explicit and revocable under GDPR.

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

What does Article 32 of GDPR address?

A

Security of processing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

What rights do data subjects have under GDPR?

A

Right to access, right to rectification, right to erasure, right to restrict processing, right to data portability, right to object.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

What is the role of the European Data Protection Board (EDPB)?

A

To ensure consistent application of GDPR across EU member states.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

Which law complements GDPR in France?

A

Loi Informatique et Libertés

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

True or False: Personal data can be processed without consent if it is necessary for the performance of a contract.

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

What is the main goal of data minimization as per GDPR?

A

To ensure only necessary data is processed.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

What is the ‘right to data portability’?

A

The right for individuals to obtain and reuse their personal data across different services.

24
Q

Fill in the blank: Under GDPR, data processing must be ________ and _________.

A

lawful; transparent

25
What does Article 6 of GDPR specify?
The lawful bases for processing personal data.
26
True or False: GDPR allows for the processing of sensitive personal data under certain conditions.
True
27
What is a 'data breach'?
A security incident that affects the confidentiality, integrity, or availability of personal data.
28
What must organizations do if they experience a data breach?
Notify the relevant supervisory authority and affected individuals if necessary.
29
Fill in the blank: The ________ is responsible for enforcing GDPR in each EU member state.
supervisory authority
30
What does the term 'data subject' refer to?
An individual whose personal data is being processed.
31
True or False: GDPR applies to personal data processed for purely personal or household activities.
False
32
What are the consequences of violating GDPR?
Fines, sanctions, and reputational damage.
33
What is the purpose of a privacy notice?
To inform data subjects about how their personal data will be processed.
34
Fill in the blank: GDPR emphasizes the importance of ________ by design and by default.
privacy
35
What does 'legitimate interest' mean in GDPR?
A legal basis for processing personal data if it does not override the rights of the data subject.
36
What is the role of consent in data processing under GDPR?
Consent must be freely given, specific, informed, and unambiguous.
37
True or False: Organizations can pre-tick consent boxes to obtain consent under GDPR.
False
38
What is the significance of Article 3 of GDPR?
It defines the territorial scope of GDPR.
39
What is a 'data processing agreement'?
A contract between a data controller and a data processor outlining data protection responsibilities.
40
Fill in the blank: The ________ must be able to demonstrate compliance with GDPR.
data controller
41
What is the 'right to object'?
The right of individuals to object to the processing of their personal data in certain circumstances.
42
True or False: GDPR allows for the transfer of personal data outside the EU under certain conditions.
True
43
What is the purpose of the 'one-stop-shop' mechanism in GDPR?
To provide a single point of contact for businesses operating in multiple EU countries.
44
Fill in the blank: GDPR requires organizations to conduct a ________ when processing high-risk data.
Data Protection Impact Assessment (DPIA)
45
What does Article 25 of GDPR address?
Data protection by design and by default.
46
What are 'special categories of personal data'?
Data that reveals racial or ethnic origin, political opinions, religious beliefs, health data, etc.
47
True or False: Data controllers are not responsible for the actions of their data processors.
False
48
What is the 'Accountability Principle' in GDPR?
Data controllers must be responsible for and able to demonstrate compliance with the GDPR.
49
Fill in the blank: Individuals can appeal decisions made by data protection authorities to the ________.
European Court of Justice
50
What is the significance of the 'Privacy Shield' framework?
It was a mechanism for transferring personal data from the EU to the US, which has since been invalidated.
51
What does Article 12 of GDPR provide for?
Transparent information, communication, and modalities for the exercise of rights.
52
True or False: Organizations must appoint a Data Protection Officer (DPO) only if they process sensitive data.
False
53
What is the purpose of the 'Right to Rectification'?
To allow individuals to correct inaccurate or incomplete personal data.
54
Fill in the blank: The GDPR encourages organizations to implement ________ measures to protect personal data.
technical and organizational
55
What is the 'Right to Restrict Processing'?
The right of individuals to limit how their personal data is processed.
56
True or False: Consent for data processing can be implied under GDPR.
False