New signups are temporarily closed.Existing customers can still sign in. Contact us to be notified when we reopen.
Skip to main content

GDPR

GDPR Advanced

Deep GDPR scenarios covering joint controllership, international transfers, enforcement mechanics, and complex data subject rights.

16 questions ยท 80% to pass ยท free

eurocompliant.com is not an accredited certification body. This is a self-paced educational assessment; the certificate confirms completion only, not a professional, statutory, or accredited qualification.

Your details

We'll email your certificate here if you pass. We may occasionally follow up about eurocompliant.com - you can unsubscribe any time.

Question 1 of 16

Two organisations jointly determine the purposes and means of processing the same personal data. Under Article 26, what must they do?

Question 2 of 16

Following Schrems II, what did the CJEU require in addition to relying on Standard Contractual Clauses for a third-country transfer?

Question 3 of 16

Which of the following can constitute 'supplementary measures' to address a transfer impact assessment finding of risk?

Select all that apply.

Question 4 of 16

Article 9 concerns 'special categories' of personal data. Which of the following is NOT listed as a special category?

Question 5 of 16

Under Article 9(2), which is a recognised condition for processing special category data?

Question 6 of 16

The 'one-stop-shop' mechanism under GDPR allows a controller with cross-border processing to primarily deal with which supervisory authority?

Question 7 of 16

Which of the following are among the criteria in Article 83(2) that supervisory authorities must consider when deciding whether to impose a fine and its amount?

Select all that apply.

Question 8 of 16

Under Article 17 (right to erasure), which is a recognised ground for a controller to refuse an erasure request?

Question 9 of 16

Article 20 (right to data portability) applies to personal data processed on which legal bases?

Question 10 of 16

A Binding Corporate Rules (BCR) authorisation, once approved by a supervisory authority, covers intra-group transfers only and cannot be relied upon for transfers to external processors.

Question 11 of 16

What is the general maximum period a supervisory authority has to respond to requests under the one-stop-shop cooperation and consistency mechanism before an 'urgency procedure' may apply?

Question 12 of 16

A controller relies on 'legitimate interests' under Article 6(1)(f). What must it be able to demonstrate?

Question 13 of 16

Under Article 37, which organisation is generally required to designate a DPO regardless of size?

Question 14 of 16

Which of the following are valid grounds under Article 49 for a 'derogation' allowing an international transfer in the absence of an adequacy decision or appropriate safeguards?

Select all that apply.

Question 15 of 16

Article 82 gives data subjects a right to compensation for material or non-material damage. Who bears the burden of proving they are not responsible for the event giving rise to the damage?

Question 16 of 16

Pseudonymised data that can be re-identified using additional information held separately still falls within the scope of 'personal data' under the GDPR.

0 of 16 answered