Official Bank 0/149

Privacy and Data Protection Foundation Exam (PDPF) - Exin Exam Questions

Last updated on June 20, 2026

97% Exam Compliance
149 Total Questions
1
Question
In the European Union we have: Directives and Regulations. What is the difference between them?
Options
A The regulation provides guidance for EU Member States and they can create their own laws to conform to the regulation. A directive has the force of law and all EU Member States must follow it without changing it.
B The directive provides guidance for EU member states and they can create their own laws to suit the directive. A regulation has the force of law and all EU Member States must follow it without changing it.
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

2
Question
A written contract between a controller and a processor is called a data processing agreement. According to the GDPR, what does not have to be covered in the written contract?
Options
A Which data are covered by the data processing agreement
B The technical and organizational measures implemented
C The contractor code of business ethics and conduct that is used.
D The information security and personal data breach procedures
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

3
Question
The controller responsible for the UK Child Sexual Abuse Investigation body reported a data breach to the supervisory authority in the UK on 28 February 2019. People who had registered their interest in participating in forums and debates for victims of child sexual abuse received an email that contained the email addresses of everyone else who had also registered.

Which category does this data breach fit into?
Options
A This data breach must be reported to the Data Protection Authority and the data subjects.
B It is not necessary to notify the Supervisory Authority, as this data breach presents minimal risks to the holders.
C This data breach should only be reported to the Data Protection Authority.
D This data breach should only be reported to data subjects.
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

4
Question
How does a Supervisory Authority collaborate to the application of GDPR?
Options
A Assists in the implementation of a data protection management system (at controller request).
B Monitor and enforce the application of this Regulation.
C Perform a Data Privacy Impact Analysis (DPI) at the request of the Data Protection Officer – DPO.
D Determines technical safety measures to be applied to the controller.
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

5
Question
Which of the options below best represents data protection by design?
Options
A It aims to ensure that personal data is automatically part of a protection process.
B It aims to create privacy impact analysis procedures (DPIA), notifications of breaches of privacy and fulfil requests from data subjects.
C It aims to incorporate security measures to protect data from the moment it is collected,
throughout the processing and until its destruction at the end of the process
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

Finish Practice?

Are you sure you want to finish? This will end your practice session.