GDPR

GDPR Practitioner

Applying GDPR in practice: transparency notices, automated decision-making, design obligations, and cross-border transfers.

14 questions · 75% to pass · free

eurocompliant.com is not an accredited certification body. This is a self-paced educational assessment; the certificate confirms completion only, not a professional, statutory, or accredited qualification.

Your details

We'll email your certificate here if you pass. We may occasionally follow up about eurocompliant.com - you can unsubscribe any time.

Question 1 of 14

Article 5's accountability principle requires controllers to be able to demonstrate compliance with the other principles, not just comply with them.

Question 2 of 14

Under Article 13, when personal data is collected directly from the data subject, at what point must the required privacy information generally be provided?

Question 3 of 14

Article 14 (data not obtained from the data subject) generally requires providing privacy information within what timeframe?

Question 4 of 14

Which of the following are among the six data protection principles listed in Article 5(1)?

Select all that apply.

Question 5 of 14

Article 22 gives data subjects the right not to be subject to a decision based solely on automated processing, including profiling, that produces what kind of effect?

Question 6 of 14

Which is a recognised exception allowing solely automated decision-making under Article 22(2)?

Question 7 of 14

Article 25 ('data protection by design and by default') requires controllers to implement appropriate technical and organisational measures at what stage?

Question 8 of 14

What does 'data protection by default' specifically require?

Question 9 of 14

Under Article 35, who must be consulted when carrying out a DPIA, where relevant?

Question 10 of 14

Which of the following are legitimate grounds under Chapter V for transferring personal data outside the EEA?

Select all that apply.

Question 11 of 14

Article 33 requires notifying the supervisory authority of a breach 'without undue delay and, where feasible, not later than 72 hours after having become aware of it' — what happens if notification is not made within 72 hours?

Question 12 of 14

Article 83 sets a two-tier system of administrative fines. Which infringement category attracts the higher tier (up to EUR 20 million / 4% of turnover)?

Question 13 of 14

Which role is responsible for determining the purposes and means of processing personal data?

Question 14 of 14

A processor may engage another processor (a sub-processor) without any authorisation from the controller.

0 of 14 answered