PDPF Exin Privacy and Data Protection Foundation Free Practice Exam Questions (2025 Updated)
Prepare effectively for your Exin PDPF Privacy and Data Protection Foundation certification with our extensive collection of free, high-quality practice questions. Each question is designed to mirror the actual exam format and objectives, complete with comprehensive answers and detailed explanations. Our materials are regularly updated for 2025, ensuring you have the most current resources to build confidence and succeed on your first attempt.
What is the definition of Supervisory Authority according to the GDPR?
What year did the General Data Protection Regulation (GDPR) come into force?
What is the main purpose of cookies?
What is the main objective of the “Lifecycle Protection” principle?
What is the legal status of the GDPR?
The controller responsible for the UK Child Sexual Abuse Investigation body reported a data breach to the
supervisory authority in the UK on 28 February 2019.
People who had registered their interest in participating in forums and debates for victims of child sexual abuse received an email that contained the email addresses of everyone else who had also registered.
Which category does this data breach fit into?
One of the basic principles of the General Data Protection Regulation (GDPR) is subsidiarity.
What is subsidiarity to GDPR?
In the contract between the controller and processor for the processing of personal data, which of the options below represents the sole responsibility of the Controller?
When personal data are processed, who is ultimately responsible for demonstrating compliance with the GDPR?
We know that when a personal data breach occurs, the data controller (Controller) must notify the Supervisory Authority within 72 hours, without justified delay. However, should the Controller do if it is unable to communicate within this time?
A person finds that a private videotape showing her in a very intimate situation has been published on a website. She never consented to publication and demands that the video is being removed without undue delay.
According to the GDPR, what should be done next?
How is Data Lifecycle Management (DLM) related to data protection?
A company CEO travels to a meeting in another city. He takes a notebook with information about the company’s new projects and acquisitions, which will be the subject of discussion at this meeting. These are the only data stored on the notebook.
The notebook accidentally falls into the hotel’s pool and all data is lost.
What happened, considering the General Data Protection Regulation (GDPR)?
Organizations are obliged to keep a number of records to demonstrate compliance with the GDPR. Which record is not obligatory according to the GDPR?
For processing of personal data to be legal, a number of requirements must be fulfilled.
What is a requirement for lawful personal data processing?
Subcontracting treatment is regulated by contract or other regulatory act under Union or Member State law, which links the processor to the controller.
What this contract or other regulatory act stipulates?
According to the GDPR, for which situations should a Data Protection Impact Assessment (DPIA) be conducted?
Personal data can be transferred outside of the EEA. According to the GDPR, which transfers outside the EEA are always lawful?
Someone regularly receives offers from a store where he purchased something five years ago. He wants the company to stop sending offers and to wipe his personal data.
Which aspect of the rights of a data subject in the General Data Protection Regulation (GDPR) requires the company to comply?
What is a responsibility of Supervisory Authorities in EEA countries?