Special Summer Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: get65

PECB Updated GDPR Exam Questions and Answers by hawwa

Page: 3 / 5

PECB GDPR Exam Overview :

Exam Name: PECB Certified Data Protection Officer
Exam Code: GDPR Dumps
Vendor: PECB Certification: Privacy And Data Protection
Questions: 80 Q&A's Shared By: hawwa
Question 12

Question:

According to theprinciple of data minimization, data must be:

Options:

A.

In a formwhich permits the identification of data subjectsfor no longer than is necessary.

B.

Acquired only forspecified, explicit, and legitimate purposes.

C.

Adequate, relevant, and limitedto what is necessary in relation to the purposes of processing.

D.

Stored forno more than five yearsfrom the date of collection.

Discussion
Question 13

Scenario 9:Soin is a French travel agency with the largest network of professional travel agentsthroughout Europe. They aim to create unique vacations for clients regardless of the destinations they seek. The company specializes in helping people find plane tickets, reservations at hotels, cruises, and other activities.

As any other industry, travel is no exception when it comes to GDPR compliance. Soin was directly affected by the enforcement of GDPR since its main activities require the collection and processing of customers’ data. Data collected by Soin includes customer's ID or passport details, financial and payment information, and contact information. This type of data is defined as personal by the GDPR; hence, Soin's data processing activities are built based on customer's consent.

At the beginning, as for many other companies, GDPR compliance was a complicated issue for Soin. However, the process was completed within a few months and later on the company appointed a DPO. Last year, the supervisory authority of France, requested the conduct of a data protection external audit in Soin without an early notice. To ensure GDPR compliance before an external audit was conducted, Soin organized an internal audit. The data protection internal audit was conducted by the DPO of the company. The audit was initiated by firstly confirming the accuracy of records related to all current Soin's data processing activities. The DPO considered that verifying compliance to Article 30 of GDPR would help in defining the data protection internal audit scope. The DPO noticed that not all processing activities of Soin were documented as required by the GDPR. For example, processing activities records of the company did not include a description of transfers of personal data to third countries. In addition, there was no clear description of categories of personal data processed by the company. Other areas that were audited included content of data protection policy, data retention guidelines, how sensitive data is stored, and security policies and practices. The DPO conducted interviews with some employees at different levels of the company. During the audit, the DPO came across some emails sent by Soin's clients claiming that they do not have access in their personal data stored by Soin. Soin's Customer Service Department answered the emails saying that, based on Soin's policies, a client cannot have access to personal data stored by the company. Based on the information gathered, the DPO concluded that there was a lack of employee awareness on the GDPR.

All these findings were documented in the audit report. Once the audit was completed, the DPO drafted action plans to resolve the nonconformities found. Firstly, the DPO created a new procedure which could ensure the right of access to clients. All employees were provided with GDPR compliance awareness sessions. Moreover, the DPO established a document which described the transfer of personal data to third countries and the applicability of safeguards when this transfer is done to an international organization.

Based on this scenario, answer the following question:

Soin’s DPO conducted an internal data protection audit. Is this acceptable?

Options:

A.

No, the role of the DPO is to only assist the company in conducting an internal data protection audit

B.

No, only the supervisory authority is responsible for conducting investigations in the form of internal data protection audits

C.

Yes, the DPO can conduct an internal data protection audit as part of monitoring compliance

Discussion
Question 14

Scenario:

An organization suffered apersonal data breachdue to aphishing emailattack, which allowed attackers to access employee names, email addresses, and phone numbers.

Question:

What could theDPO do to preventa similar breach from happening again?

Options:

A.

Provide training and awareness sessionson data protection within the organization.

B.

Classify incidents into categoriesand take decisions based on this categorization.

C.

Create a data breach response planthat includes information onhow breaches should behandled.

D.

Both A and C.

Discussion
Ava-Rose
Yes! Cramkey Dumps are amazing I passed my exam…Same these questions were in exam asked.
Ismail Sep 18, 2024
Wow, that sounds really helpful. Thanks, I would definitely consider these dumps for my certification exam.
Ilyas
Definitely. I felt much more confident and prepared because of the Cramkey Dumps. I was able to answer most of the questions with ease and I think that helped me to score well on the exam.
Saoirse Sep 25, 2024
That's amazing. I'm glad you found something that worked for you. Maybe I should try them out for my next exam.
Erik
Hey, I have passed my exam using Cramkey Dumps?
Freyja Oct 17, 2024
Really, what are they? All come in your pool? Please give me more details, I am going to have access their subscription. Please brother, give me more details.
Reeva
Wow what a success I achieved today. Thank you so much Cramkey for amazing Dumps. All students must try it.
Amari Sep 1, 2024
Wow, that's impressive. I'll definitely keep Cramkey in mind for my next exam.
Question 15

Which of the statements below related to compliance monitoring is correct?

Options:

A.

The DPO should monitor and measure all activities of the organization in order to ensure the suitability and effectiveness of the GDPR compliance program

B.

The DPO should monitor internal compliance of the organization with applicable data protection laws

C.

The DPO should assign roles and responsibilities to monitor GDPR compliance

Discussion
Page: 3 / 5

GDPR
PDF

$36.75  $104.99

GDPR Testing Engine

$43.75  $124.99

GDPR PDF + Testing Engine

$57.75  $164.99