According to the principle of purpose limitation, data should not be processed beyond the legitimate purpose defined. However, further processing is allowed in a few specific cases, provided that appropriate safeguards for the rights and freedoms of the data subjects are taken. For which purpose is further processing not allowed?
Answer : D
For archiving purposes in the public interest. Incorrect. With the safeguards in place, further processing is
allowed for archiving purposes in the public interest.
For direct marketing and commercial purposes. Correct. This is not a purpose that is allowed, if it is not the original legitimate purpose of the processing. (Literature: A, Chapter 2)
For generalized statistical purposes. Incorrect. With the safeguards in place, further processing is allowed for generalized statistical purposes.
For scientific or historical research purposes. Incorrect. With the safeguards in place, further processing is allowed for research purposes.
Data protection and privacy are closely related terms. Which of these options best represent this relationship?
Answer : D
A very repeated phrase is: ''It is possible to have security without privacy, but it is not possible to have privacy without security''.
Privacy is a right that should be protected, and Data Protection are the measures that will be used to achieve this protection.
Which EU legislation allows data to be transferred between the European Economic Area (EEA) and the United States (USA)?
Answer : A
In July 2016, Implementing Decision 2016/1250 came into force, which legislates that the United States must ensure an adequate level of protection for personal data transferred from the Union to United States organizations under the EU-US Privacy Protection Shield (Privacy Shield).
This is because the United States does not have a single law on the protection of personal data, since because of its internal policy, each state can create its own laws. Privacy Shield aims to standardize this, so that companies in the European Union and the United States can offer their services.
Article 1 of the Implementing Decision 2016/1250:
1. For the purposes of Article 25(2) of Directive 95/46 / EC, the United States ensures an adequate level of protection for personal data transferred from the Union to organisations in the United States under the
EU-U.S. Privacy Shield.
2. The EU-U.S. Privacy Shield is constituted by the Principles issued by the U.S. Department of Commerce on 7 July 2016 as set out in Annex II and the official representations and commitments contained in the documents listed in Annexes I, III to VI.
3. For the purpose of paragraph 1, personal data are transferred under the EU-U.S. Privacy Shield where they are transferred from the Union to organisations in the United States that are included in the 'Privacy Shield List', maintained and made publicly available by the U.S. Department of Commerce, in accordance with Sections I and III of the Principles set out in Annex II.
A company's director's notebook is accidentally wet, which permanently damages the equipment so that it cannot recover its data.
The lost data concerned the financial reports of the company. What happened in this case according to GDPR?
Answer : C
The lost reports did not contain personal data, in this case GDPR is not applicable and is a security incident.
Important
A data breach is whenever something that has not been planned with personal data happens, be it improper processing, improper sharing, loss of data, deletion, etc. In other words, personal data must be used for a specific purpose, respecting the life cycle of the same (from collection to exclusion), any situation that escapes this cycle must be reported as a data breach.
What is the most important difference between the 95/46/EC and the GDPR?
Answer : D
How does a Supervisory Authority collaborate to the application of GDPR?
Answer : B
Article 57 legislates on the Responsibilities of the Supervisory Authority. In paragraph 1, item ''a'' says: ''monitor and enforce the application of this Regulation''.
A person buys a product at a store located in the European Economic Area (EEA). At the time of purchase, you are asked to fill out a registration form and he informs his personal email.
As is usual in many stores, in the next few days this person will start receiving several marketing emails. He considers the frequency of these emails to be very high. Demanding his rights, he asks the store to delete all his personal data.
What the store must do according to the General Data Protection Regulation (GDPR)?
Answer : C
Companies have tax obligations to be fulfilled, so financial data cannot be deleted.
The data subject has several rights under the GDPR, however there are limitations. These rights cannot run counter to other specific legislation. In this case, the holder can exercise the right of Opposition instead of Exclusion. In the Right of Opposition, he requests the Controller to cease the processing of his data for non- consented purposes. An example of Opposition: in Brazil there was the website naomeperturbe.com.br, where millions of Brazilians could oppose the inconvenient calls made by the telecommunication service providers.