CSC GDPR Data Protection Principles 2 — Questions and Answers
Question 1: Under GDPR's storage limitation principle, personal data must be kept in a form that permits identification of data subjects for no longer than:
- The duration the controller deems necessary
- As long as the data subject consents to storage
- No longer than is necessary for the purposes for which it is processed (Correct answer)
- A maximum of five years under all circumstances
Correct answer: No longer than is necessary for the purposes for which it is processed
The storage limitation principle requires that personal data is kept only as long as necessary for its specified purpose, after which it must be deleted or anonymized.
Question 2: A healthcare provider collects patient data for treatment but later wants to use it for marketing. Under GDPR's purpose limitation principle, this secondary use is:
- Permitted if the data was already collected
- Permitted only with a new explicit consent from patients (Correct answer)
- Automatically compatible because healthcare is a legitimate interest
- Permitted without restriction since the data is already held
Correct answer: Permitted only with a new explicit consent from patients
Purpose limitation prohibits using data for incompatible secondary purposes; marketing is incompatible with treatment, so fresh explicit consent is required.
Question 3: Which GDPR principle requires that personal data must be accurate and, where necessary, kept up to date?
- Storage limitation
- Data minimisation
- Accuracy (Correct answer)
- Integrity and confidentiality
Correct answer: Accuracy
The accuracy principle mandates that inaccurate personal data must be erased or rectified without delay.
Question 4: An e-commerce site collects a customer's full medical history during checkout 'just in case it's useful later.' Which GDPR principle is most directly violated?
- Lawfulness
- Data minimisation (Correct answer)
- Storage limitation
- Accountability
Correct answer: Data minimisation
Data minimisation requires that only data adequate, relevant, and limited to what is necessary for the specified purpose is collected.
Question 5: The GDPR principle of 'integrity and confidentiality' most directly requires controllers to:
- Publish their data processing activities publicly
- Ensure data is processed using appropriate technical and organisational security measures (Correct answer)
- Limit data retention to 90 days by default
- Obtain a data protection officer for all processing
Correct answer: Ensure data is processed using appropriate technical and organisational security measures
Integrity and confidentiality (security principle) mandates appropriate technical and organisational measures to protect data against unauthorised access, loss, or destruction.
Question 6: Under the accountability principle, which of the following best demonstrates compliance?
- Verbally assuring regulators that data is handled correctly
- Maintaining documented records of processing activities and impact assessments (Correct answer)
- Delegating all compliance decisions to processors
- Publishing annual revenue figures
Correct answer: Maintaining documented records of processing activities and impact assessments
Accountability requires controllers to be able to demonstrate compliance through records, policies, DPIAs, and other documented evidence.
Question 7: A company pseudonymises customer data before using it for analytics. Under GDPR, pseudonymised data is:
- No longer personal data and fully exempt from GDPR
- Still personal data if re-identification is possible (Correct answer)
- Treated identically to fully anonymised data
- Exempt from all data minimisation requirements
Correct answer: Still personal data if re-identification is possible
Pseudonymised data remains personal data under GDPR because re-identification is possible when combined with additional information held by the controller.
Under GDPR's storage limitation principle, personal data must be kept in a form that permits identification of data subjects for no longer than: