GDPR

GDPR Advanced

Deep GDPR scenarios covering joint controllership, international transfers, enforcement mechanics, and complex data subject rights.

16 questions ยท 80% to pass ยท free

eurocompliant.com is not an accredited certification body. This is a self-paced educational assessment; the certificate confirms completion only, not a professional, statutory, or accredited qualification.

Your details

We'll email your certificate here if you pass. We may occasionally follow up about eurocompliant.com - you can unsubscribe any time.

Question 1 of 16

Two organisations jointly determine the purposes and means of processing the same personal data. Under Article 26, what must they do?

Question 2 of 16

Following Schrems II, what did the CJEU require in addition to relying on Standard Contractual Clauses for a third-country transfer?

Question 3 of 16

Which of the following can constitute 'supplementary measures' to address a transfer impact assessment finding of risk?

Select all that apply.

Question 4 of 16

Article 9 concerns 'special categories' of personal data. Which of the following is NOT listed as a special category?

Question 5 of 16

Under Article 9(2), which is a recognised condition for processing special category data?

Question 6 of 16

The 'one-stop-shop' mechanism under GDPR allows a controller with cross-border processing to primarily deal with which supervisory authority?

Question 7 of 16

Which of the following are among the criteria in Article 83(2) that supervisory authorities must consider when deciding whether to impose a fine and its amount?

Select all that apply.

Question 8 of 16

Under Article 17 (right to erasure), which is a recognised ground for a controller to refuse an erasure request?

Question 9 of 16

Article 20 (right to data portability) applies to personal data processed on which legal bases?

Question 10 of 16

A Binding Corporate Rules (BCR) authorisation, once approved by a supervisory authority, covers intra-group transfers only and cannot be relied upon for transfers to external processors.

Question 11 of 16

What is the general maximum period a supervisory authority has to respond to requests under the one-stop-shop cooperation and consistency mechanism before an 'urgency procedure' may apply?

Question 12 of 16

A controller relies on 'legitimate interests' under Article 6(1)(f). What must it be able to demonstrate?

Question 13 of 16

Under Article 37, which organisation is generally required to designate a DPO regardless of size?

Question 14 of 16

Which of the following are valid grounds under Article 49 for a 'derogation' allowing an international transfer in the absence of an adequacy decision or appropriate safeguards?

Select all that apply.

Question 15 of 16

Article 82 gives data subjects a right to compensation for material or non-material damage. Who bears the burden of proving they are not responsible for the event giving rise to the damage?

Question 16 of 16

Pseudonymised data that can be re-identified using additional information held separately still falls within the scope of 'personal data' under the GDPR.

0 of 16 answered