Heads up: opening this section reveals every question, every option, and the correct answer for this round. If you came here to play, scroll up and hit Play first.
Question 1: What term describes an individual associated with collected personal data?
- Data subject
- Data controller
- Data processor
- Data analyst
Answer: A. Data subject
Explanation: A data subject is the specific individual whose personal information is being collected, stored, or processed by an organization or entity.
Question 2: Which term refers to information that can identify or is linkable to an individual?
- Aggregate data
- Metadata
- Public domain
- Personally identifiable information
Answer: D. Personally identifiable information
Explanation: Personally identifiable information (PII) is any data that can be used to determine an individual's identity or is directly linkable to them.
Question 3: What is the principle of collecting only the minimum data necessary for a specific purpose?
- Data encryption
- Data dissemination
- Data minimization
- Purpose limitation
Answer: C. Data minimization
Explanation: Data minimization is a best practice asserting that organizations should only collect the absolute minimum amount of personal data required for their stated goal.
Question 4: Which entity is responsible for determining the purposes and means of processing personal data?
- Data auditor
- Data processor
- Data controller
- Data subject
Answer: C. Data controller
Explanation: A data controller is the entity that makes the decisions regarding why and how personal data is processed within an organization's workflow.
Question 5: What is the term for an entity that processes personal data on behalf of a data controller?
- Data processor
- Data analyst
- Data subject
- Data owner
Answer: A. Data processor
Explanation: A data processor is an entity that performs operations on personal data specifically on behalf of and under the instructions of a data controller.
Question 6: What is a freely given, specific, and informed indication of will by a data subject?
- Consent
- Notification
- Contract
- Policy
Answer: A. Consent
Explanation: Consent is a formal, informed agreement provided by a data subject, allowing an organization to collect or process their personal information.
Question 7: What is a request made by a data subject to exercise their rights over their collected data?
- Data audit
- Data deletion notice
- Data subject access request
- Data breach report
Answer: C. Data subject access request
Explanation: A DSAR, or Data Subject Access Request, is a formal request allowing individuals to exercise their legal rights regarding their personal data held by organizations.
Question 8: What is information that cannot be traced to an individual, even when combined with other data?
- Public data
- Personal data
- Anonymous data
- Encrypted data
Answer: C. Anonymous data
Explanation: Anonymous data is information that has been stripped of identifiers so that it cannot be traced back to a specific person, even with additional context.
Question 9: Which of these is considered a valid legal basis for processing data under the GDPR?
- Marketing convenience
- Corporate profit
- Legitimate interest
- Internal curiosity
Answer: C. Legitimate interest
Explanation: Legitimate interest is one of the six recognized legal bases for processing data under the GDPR, alongside consent, legal obligation, and others.
Question 10: What process converts information into a coded format to prevent unauthorized access?
- Data encryption
- Data anonymization
- Data dissemination
- Data minimization
Answer: A. Data encryption
Explanation: Data encryption is a security measure that transforms readable information into a coded format, ensuring that only authorized parties can access the content.