Join the discussion
Question 1/140
An organization receives a request multiple times from a data subject seeking to exercise his rights with respect to his own personal data. Under what condition can the organization charge the data subject a fee for processing the request?
Correct Answer: D
Add Comments
- Other Question (140q)
- Q1. An organization receives a request multiple times from a data subject seeking to exercise ...
- Q2. Under which of the following conditions does the General Data Protection Regulation NOT ap...
- Q3. Which of the following would most likely NOT be covered by the definition of "personal dat...
- Q4. Which change was introduced by the 2009 amendments to the e-Privacy Directive 2002/58/EC?...
- Q5. The GDPR's list of processor obligations regarding cloud computing includes all of the fol...
- Q6. Which of the following is NOT recognized as being a common characteristic of cloud-computi...
- Q7. What type of data lies beyond the scope of the General Data Protection Regulation?...
- Q8. Which of the following would MOST likely trigger the extraterritorial effect of the GDPR, ...
- Q9. SCENARIO Please use the following to answer the next question: ProStorage is a multination...
- Q10. Many businesses print their employees' photographs on building passes, so that employees c...
- Q11. What is the consequence if a processor makes an independent decision regarding the purpose...
- Q12. According to Article 14 of the GDPR, how long does a controller have to provide a data sub...
- Q13. A U.S. company's website sells widgets. Which of the following factors would NOT in itself...
- Q14. SCENARIO Please use the following to answer the next question: Gentle Hedgehog Inc. is a p...
- Q15. According to the European Data Protection Board, controllers responding to a data subject ...
- Q16. Why is advisable to avoid consent as a legal basis for an employer to process employee dat...
- Q17. Which of the following is NOT exempt from the material scope of the GDPR. insofar as the p...
- Q18. A grade school is planning to use facial recognition to track student attendance. Which of...
- Q19. What is the main task of the European Data Protection Board?...
- Q20. Under Article 80(1) of the GDPR, individuals can elect to be represented by not-for-profit...
- Q21. SCENARIO Please use the following to answer the next question: TripBliss Inc. is a travel ...
- Q22. Jerry the Chief Marketing Officer for a sports apparel and trophy company, sells products ...
- Q23. A news website based m (he United Slates reports primarily on North American events The we...
- Q24. Based on GDPR Article 35, which of the following situations would trigger the need to comp...
- Q25. Which of the following elements does NOT need to be presented to a data subject in order t...
- Q26. In the EDPB's Guidelines 4/2019 on Article 25 Data Protection by Design and by Default, al...
- Q27. You have just been hired by a toy manufacturer based in Hong Kong. The company sells a bro...
- Q28. ISO 31700 has set forth requirements relating to consumer products and services. In partic...
- Q29. SCENARIO Please use the following to answer the next question: Anna and Frank both work at...
- Q30. SCENARIO Please use the following to answer the next question: T-Craze, a German-headquart...
- Q31. Which of the following is NOT a role of works councils?...
- Q32. If a French controller has a car-sharing app available only in Morocco, Algeria and Tunisi...
- Q33. SCENARIO Please use the following to answer the next question: Brady is a computer program...
- Q34. The GDPR specifies fines that may be levied against data controllers for certain infringem...
- Q35. A company plans to transfer employee health information between two of its entities in Fra...
- Q36. SCENARIO Please use the following to answer the next question: Brady is a computer program...
- Q37. A data controller appoints a data protection officer. Which of the following conditions wo...
- Q38. An unforeseen power outage results in company Z's lack of access to customer data for six ...
- Q39. Which GDPR principle would a Spanish employer most likely depend upon to annually send the...
- Q40. According to Art 23 GDPR, which of the following data subject rights can NOT be restricted...
- Q41. Which of the following demonstrates compliance with the accountability principle found in ...
- Q42. Under what circumstances would the GDPR apply to personal data that exists in physical for...
- Q43. Since blockchain transactions are classified as pseudonymous, are they considered to be wi...
- Q44. In the Planet 49 case, what was the man judgement of the Coon of Justice of the European U...
- Q45. As a result of the European Court of Justice's ruling in the case of Google v. Spain, sear...
- Q46. Bioface is a company based in the United States. It has no servers, personnel or assets in...
- Q47. SCENARIO Please use the following to answer the next question: Financially, it has been a ...
- Q48. SCENARIO Please use the following to answer the next question: Javier is a member of the f...
- Q49. SCENARIO Please use the following to answer the next question: Jack worked as a Pharmacovi...
- Q50. In addition to the European Commission, who can adopt standard contractual clauses, assumi...
- Q51. SCENARIO Please use the following to answer the next question: Due to rapidly expanding wo...
- Q52. The European Parliament jointly exercises legislative and budgetary functions with which o...
- Q53. In the wake of the Schrems II ruling, which of the following actions has been recommended ...
- Q54. Which of the following does NOT have to be included in the records most processors must ma...
- Q55. SCENARIO Please use the following to answer the next question: Jack worked as a Pharmacovi...
- Q56. SCENARIO Please use the following to answer the next question: Due to rapidly expanding wo...
- Q57. What permissions are required for a marketer to send an email marketing message to a consu...
- Q58. Assuming that the "without undue delay" provision is followed, what is the time limit for ...
- Q59. Which EU institution is vested with the competence to propose new data protection legislat...
- Q60. When would a data subject NOT be able to exercise the right to portability?...
- Q61. SCENARIO Please use the following to answer the next question: Joe started the Gummy Bear ...
- Q62. Read the following steps: * Discover which employees are accessing cloud services and from...
- Q63. What is one major goal that the OECD Guidelines, Convention 108 and the Data Protection Di...
- Q64. The GDPR requires controllers to supply data subjects with detailed information about the ...
- Q65. Which of the following regulates the use of electronic communications services within the ...
- Q66. What must a data controller do in order to make personal data pseudonymous?...
- Q67. According to the EDPB Guidelines 01/2021 on Examples regarding Personal Data Breach Notifi...
- Q68. SCENARIO Please use the following to answer the next question: Louis, a long-time customer...
- Q69. Which sentence best describes proper compliance for an international organization using Bi...
- Q70. A mobile device application that uses cookies will be subject to the consent requirement o...
- Q71. What term BEST describes the European model for data protection?...
- Q72. In relation to third countries and international organizations, which of the following sha...
- Q73. Which of the following is an example of direct marketing that would be subject to European...
- Q74. A homeowner has installed a motion-detecting surveillance system that films his front doc ...
- Q75. SCENARIO Please use the following to answer the next question: You have just been hired by...
- Q76. Through a combination of hardware failure and human error, the decryption key for a bank's...
- Q77. Which sentence BEST summarizes the concepts of "fairness," "lawfulness" and "transparency"...
- Q78. WP29's "Guidelines on Personal data breach notification under Regulation 2016/679'' provid...
- Q79. SCENARIO Please use the following to answer the next question: The fitness company Vigotro...
- Q80. If two controllers act as joint controllers pursuant to Article 26 of the GDPR, which of t...
- Q81. SCENARIO Please use the following to answer the next question: Liem, an online retailer kn...
- Q82. SCENARIO Please use the following to answer the next question: Building Block Inc. is a mu...
- Q83. SCENARIO Please use the following to answer the next question: Joe started the Gummy Bear ...
- Q84. For which of the following operations would an employer most likely be justified in reques...
- Q85. The Murla HB Club should have carried out a DPIA before the installation of the new access...
- Q86. SCENARIO Please use the following to answer the next question: Joe is the new privacy mana...
- Q87. A company is hesitating between Binding Corporate Rules and Standard Contractual Clauses a...
- Q88. A U.S.-based online shop uses sophisticated software to track the browsing behavior of its...
- Q89. Under Article 21 of the GDPR, a controller must stop profiling when requested by a data su...
- Q90. An organization conducts body temperature checks as a part of COVID-19 monitoring. Body te...
- Q91. Which kind of privacy notice, originally advocated by the Article 29 Working Party, is com...
- Q92. SCENARIO Please use the following to answer the next question: Why was Jackie correct in n...
- Q93. Article 58 of the GDPR describes the power of supervisory authorities. Which of the follow...
- Q94. According to the GDPR. Article 4(14). biometric data is defined as: "Personal data resulti...
- Q95. The EDPB's Guidelines 8/2020 on the targeting of social media users stipulates that in ord...
- Q96. SCENARIO Please use the following to answer the next question: Financially, it has been a ...
- Q97. SCENARIO Please use the following to answer the next question: WonderkKids provides an onl...
- Q98. Under what circumstances might the "soft opt-in" rule apply in relation to direct marketin...
- Q99. Which statement is correct when considering the right to privacy under Article 8 of the Eu...
- Q100. Which judicial body makes decisions on actions taken by individuals wishing to enforce the...
- Q101. A Spanish electricity customer calls her local supplier with Questions: about the company'...
- Q102. According to the European Data Protection Board, data subjects should be aware of any vide...
- Q103. SCENARIO Please use the following to answer the next question: Joe is the new privacy mana...
- Q104. Which statement provides an accurate description of a directive?...
- Q105. When collecting personal data in a European Union (EU) member state, what must a company d...
- Q106. What is the main purpose of the EU Data Act?
- Q107. Under the GDPR, where personal data is not obtained directly from the data subject, a cont...
- Q108. According to the GDPR, what is the main task of a Data Protection Officer (DPO)?...
- Q109. SCENARIO - Please use the following to answer the next question: It has been a tough seaso...
- Q110. Which mechanism, new to the GDPR, now allows for the possibility of personal data transfer...
- Q111. What must be included in a written agreement between the controller and processor in relat...
- Q112. After detecting an intrusion involving the theft of unencrypted personal data, who shall t...
- Q113. What is true of both the General Data Protection Regulation (GDPR) and the Council of Euro...
- Q114. SCENARIO Please use the following to answer the next question: The fitness company Vigotro...
- Q115. Which of the following is an accurate statement regarding the "one-stop-shop" mechanism of...
- Q116. SCENARIO Please use the following to answer the next question: T-Craze, a German-headquart...
- Q117. If a company is planning to use closed-circuit television (CCTV) on its premises and is co...
- Q118. According to the GDPR, how is pseudonymous personal data defined?...
- Q119. If a multi-national company wanted to conduct background checks on all current and potenti...
- Q120. A company wishes to transfer personal data to a country outside of the European Union/EEA ...
- Q121. What monitoring may lawfully be performed within the scope of Gentle Hedgehog's business?...
- Q122. Which failing of Privacy Shield, cited by the CJEU as a reason for its invalidation, is th...
- Q123. SCENARIO Please use the following to answer the next question: ABC Hotel Chain and XYZ Tra...
- Q124. Which of the following Convention 108+ principles, as amended in 2018, is NOT consistent w...
- Q125. When assessing the level of risk created by a data breach, which of the following would NO...
- Q126. SCENARIO Please use the following to answer the next question: Liem, an online retailer kn...
- Q127. According to the E-Commerce Directive 2000/31/EC, where is the place of "establishment" fo...
- Q128. Which of the following is the weakest lawful basis for processing employee personal data?...
- Q129. How can the relationship between the GDPR and the Digital Services Act, the Data Governanc...
- Q130. SCENARIO Please use the following to answer the next question: Liem, an online retailer kn...
- Q131. To which of the following parties does the territorial scope of the GDPR NOT apply?...
- Q132. To provide evidence of GDPR compliance, a company performs an internal audit. As a result,...
- Q133. Under the Data Protection Law Enforcement Directive of the EU, a government can carry out ...
- Q134. What was the main failing of Convention 108 that led to the creation of the Data Protectio...
- Q135. SCENARIO Please use the following to answer the next question: Building Block Inc. is a mu...
- Q136. SCENARIO Please use the following to answer the next question: Joe is the new privacy mana...
- Q137. When is data sharing agreement MOST likely to be needed?...
- Q138. SCENARIO Please use the following to answer the next question: Anna and Frank both work at...
- Q139. As per the GDPR, which legal basis would be the most appropriate for an online shop that w...
- Q140. SCENARIO Please use the following to answer the next question: TripBliss Inc. is a travel ...
