MultipleChoice
Based on GDPR Article 35, Which option best situations would trigger the need to complete a DPIA?
OptionsMultipleChoice
What is true if an employee makes an access request to his employer for any personal data held about him?
OptionsMultipleChoice
When assessing the level of risk created by a data breach, which of the following would NOT have to be taken into consideration?
OptionsMultipleChoice
Pursuant to Article 4(5) of the GDPR, data is considered ''pseudonymized'' if?
OptionsMultipleChoice
What is the consequence if a processor makes an independent decision regarding the purposes and means of processing it carries out on behalf of a controller?
OptionsMultipleChoice
SCENARIO
Please use the following to answer the next question:
Jack worked as a Pharmacovigiliance Operations Specialist in the Irish office of a multinational pharmaceutical company on a clinical trial related to COVID-19. As part of his onboarding process Jack received privacy training He was explicitly informed that while he would need to process confidential patient data in the course of his work, he may under no circumstances use this data for anything other than the performance of work-related (asks This was also specified in the privacy policy, which Jack signed upon conclusion of the training.
After several months of employment, Jack got into an argument with a patient over the phone. Out of anger he later posted the patient's name and hearth information, along with disparaging comments, on a social media website. When this was discovered by his Pharmacovigilance supervisors. Jack was immediately dismissed
Jack's lawyer sent a letter to the company stating that dismissal was a disproportionate sanction, and that if Jack was not reinstated within 14 days his firm would have no alternative but to commence legal proceedings against the company. This letter was accompanied by a data access request from Jack requesting a copy of "all personal data, including internal emails that were sent/received by Jack or where Jack is directly or indirectly identifiable from the contents. In relation to the emails Jack listed six members of the management team whose inboxes the required access.
How should the company respond to Jack's request to be forgotten?
OptionsMultipleChoice
What is an important difference between the European Court of Human Rights (ECHR) and the Court of Justice of the European Union (CJEU) in relation to their roles and functions?
OptionsMultipleChoice
According to the AI Act, a provider of a high-risk AI system has all of the following obligations EXCEPT?
A. Ensuring users understand how the system mitigates bias. B. Registering the system in the European AI Board's database. C. Providing detailed documentation about the system to the users. D. Conducting a conformity assessment before placing the system on the market.
OptionsMultipleChoice
What is the main purpose of the EU Data Act?
A. To enable the processing and transfer of non-personal data within the EU. B. To allow users of connected devices to access data generated by their use. C. To facilitate the voluntary sharing of data between individuals and businesses. D. To regulate individuals' privacy rights and the processing of their personal data.
OptionsMultipleChoice
Once an organization has conducted an internal investigation to determine the scope of a ransomware attack, what is the appropriate next step in the process?
A. Assess the risks associated with the breach and, if necessary, notify affected individuals and regulatory bodies within the relevant timeframes. B. Notify law enforcement and consult with legal counsel to understand the implications of the breach and the notification requirements. C. Inform all customers and the public via social media platforms to ensure rapid dissemination of relevant information. D. Wait for law enforcement to provide guidance on notification procedures before taking any further action.
Options