Free PDPF Practice Test Questions and Answers (2026) | Cert Empire Practice Questions
Free preview: 20 questions.
EXIN PDPF
Q: 1
What is the essence of the principle ‘Full Lifecycle Protection’?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 2
What is the term used in the General Data Protection Regulation (GDPR) for the disclosure of, or
unauthorized access to, personal data?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 3
A Belgian company has their headquarters in France for tax purposes. They enter into a legally
binding contract with a processor in the Netherlands for the processing of personal data of data
subjects with various nationalities. A personal data breach occurs. The supervisory authorities start
an investigation. Why is the French supervisory authority seen as the lead supervisory authority?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 4
According to the General Data Protection Regulation (GDPR), which category of personal data is
considered to be sensitive data?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 5
Which of these should appear in a Data Protection Impact Assessment (DPIA) according to the
General Data Protection Regulation (GDPR)?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 6
According to the GDPR, when is a data protection impact assessment (DPIA) obligatory?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 7
Some data processing falls outside of the material scope of the GDPR. What type of processing is not
subject to the GDPR?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 8
According to the GDPR, what is a task of a supervisory authority?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 9
The GDPR does not define privacy as a term but uses the concept implicitly throughout the text.
What is a correct definition of privacy as implicitly used throughout the GDPR?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 10
Which of the following has a data breach under the General Data Protection Regulation (GDPR)?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 11
What is the purpose of a data protection audit by the supervisory authority?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 12
A person is moving from city A to city B, within an EEA member state. In city A he was a patient of the local hospital A. In city B, he becomes a patient of hospital B. The patient has opted out of the national electronic patients file system. The patient asks hospital A to forward his medical file directly to hospital B. According to the GDPR, what is allowed?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 13
Your credit card has been cloned. A card contains various personal information.
What category of data breach is this incident?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 14
After appearing in a photo posted by a friend on a social network, a person felt embarrassed and
decided that he wants the photo to be deleted.
According to the General Data Protection Regulation (GDPR), does that person have the right to
delete this photo?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 15
The Control Authority may impose fines on organizations that are not meeting the mandatory
requirements of the General Data Protection Regulation (GDPR).
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 16
What is the relationship between data protection and privacy?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 17
Which cause is a data breach according to the GDPR?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 18
According to Article.33 of the GDPR the controller shall without undue delay and, where feasible, not
later than 72 hours after having become aware of it, notify the personal data breach to the
supervisory authority. What is the maximum penalty for non-compliance with this notification
obligation?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 19
The General Data Protection Regulation (GDPR) formalizes the data subject’s right to data portability.
What is the objective of data portability?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 20
A German company wants to enter into a binding contract with a processor in the Netherlands for
the processing of sensitive personal data of German data subjects. The Dutch Supervisory Authority
is informed of the type of data and the aims of the processing, including the contract describing what
data will be processed and what data protection procedures and practices will be in place.
According to the GDPR, what should the Dutch Supervisory Authority do in this scenario?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Question 1 of 20