This multiple choice assessment focuses on the new General Data Protection Regulation (GDPR).
The purpose of the assessment is to enable you to assess the extent and depth of your knowledge of the Data Protection Law in preparation for the DPL.
Format: Multiple Choice
Time: 90 minutes
The result will be provided immediately, with details on all questions.
1) When processing personal data under the authority of the controller or processor, a processor may process data on instructions from the controller and also:
2) A controller engages a processor to handle payroll data for its employees. Under Article 28 of the GDPR, which of the following is NOT a mandatory element that must be included in the data processing agreement between the controller and the processor?
3) A processor, after processing personal data on behalf of a controller for the duration of a service contract, is unsure what it must do with the personal data once the contract ends. According to Article 28(3)(g) GDPR, what is the processor's default obligation regarding the personal data at the end of the provision of services, unless EU or Member State law requires storage of the data?
4) A cloud-based email marketing platform allows businesses to upload their customer email lists and send marketing campaigns. The platform determines the technical means of processing (server infrastructure, security measures, encryption standards) but has no say in whose data is uploaded, what the emails contain, or when campaigns are sent, all of which is decided entirely by the businesses using the platform. Under the GDPR, what role does the email marketing platform play with respect to the customer email data?
5) A hospital contracts an external IT company to host and maintain its patient records database. The hospital decides what patient data is collected, how long it is retained, who within the hospital may access it, and the purposes for which it is used (treatment, billing, etc.). The IT company only accesses the data when troubleshooting technical issues, strictly following the hospital's written instructions, and is contractually prohibited from using the data for any other purpose. One day, the IT company decides on its own initiative and without informing the hospital to use anonymized excerpts of the patient data to train its own internal diagnostic software product for resale to other clients. What is the most likely GDPR classification of the IT company with respect to this new use?