After notifying the supervisory authority, what should be the first action the controller must take when it finds a security breach where unauthorized people have accessed personal data?
After appearing in a photo posted by a friend on a social network, a person felt embarrassed and decided that he wants the photo to be deleted.
According to the General Data Protection Regulation (GDPR), does that person have the right to delete this photo?
In what way are online activities of people most effectively used by modern marketers?
The Control Authority may impose fines on organizations that are not meeting the mandatory requirements of the General Data Protection Regulation (GDPR).
The General Data Protection Regulation (GDPR) is often known as the “European privacy law”. What is the relationship between ‘privacy’ and ‘data protection’?
According to the principle of purpose limitation, data should not be processed beyond the legitimate purpose defined. However, further processing is allowed in a few specific cases, provided that appropriate safeguards for the rights and freedoms of the data subjects are taken. For which purpose is further processing not allowed?
A written contract between a controller and a processor is called a data processing agreement. According to
the GDPR, what does not have to be covered in the written contract?
What is a responsibility of Supervisory Authorities in EEA countries?
What year did the General Data Protection Regulation (GDPR) come into force?
When does the GDPR require data subjects consent to a cookie?
Which condition below allows personal data to be processed legally?
While paying with a credit card, the card is skimmed (i.e. the data on the magnetic strip is stolen). The magnetic strip contains the account number, expiration date, cardholder’s name and address, PIN number and more.
What kind of a data breach is this?
According to the GDPR, in what situation must data subjects always be notified of a personal data breach?
Which EU legislation allows data to be transferred between the European Economic Area (EEA) and the United States (USA)?
What is the relationship between data protection and privacy?
Personal data can be transferred outside of the EEA. According to the GDPR, which transfers outside the EEA are always lawful?
What is considered a personal data processing for the General Data Protection Regulation (GDPR)?
The GDPR contains several items. Which of these contains mandatory requirements?
A person finds that a private videotape showing her in a very intimate situation has been published on a website. She never consented to publication and demands that the video is being removed without undue delay.
According to the GDPR, what should be done next?
Which of the options below is classified as a personal data breach under the GDPR?
The General Data Protection Regulation (GDPR) in its Article 30 legislates on the Records of treatment activities.
If requested, the controller must provide these records:
What is the main reason for performing data protection by design (from conception)?