โ† All CSC Flashcard Decks

GDPR Data Protection Principles Flashcards

7 cards from real CSC practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 GDPR Data Protection Principles flashcards as text
  1. A fintech startup uses open banking data to build credit scores. Under GDPR's purpose limitation principle, they must ensure:

    Answer: The credit scoring purpose was specified before or at the time of collection

    Purpose limitation requires that the purpose for which data is used is specified at or before the time of collection, not retroactively.

  2. GDPR's data minimisation principle is best summarised by which phrase?

    Answer: Adequate, relevant, and limited to what is necessary

    Data minimisation means personal data must be adequate (sufficient for the purpose), relevant, and limited to what is strictly necessary.

  3. A breach of the integrity and confidentiality principle could result from which of the following?

    Answer: Storing unencrypted personal data on a publicly accessible server

    Storing personal data without encryption on a public server violates the security principle because it fails to protect against unauthorized access.

  4. Under GDPR, which of the following is an example of processing data in a manner compatible with the original collection purpose?

    Answer: Collecting research survey data and archiving it in the public interest

    Archiving in the public interest is explicitly recognized by GDPR as a compatible further purpose under Article 5(1)(b).

  5. A controller claims they anonymised their dataset, but re-identification is possible using publicly available data. Under GDPR, this dataset should be treated as:

    Answer: Personal data subject to all GDPR principles

    If re-identification is reasonably possible, the data is still personal data under GDPR regardless of the controller's anonymisation claims.

  6. For the transparency component of GDPR's first principle, controllers must provide privacy information that is:

    Answer: Concise, transparent, intelligible, and easily accessible

    Transparency requires that privacy information be concise, transparent, intelligible, easily accessible, and written in clear, plain language.

  7. Which of the following correctly describes the relationship between the six GDPR data protection principles under Article 5?

    Answer: They are legally binding obligations that all controllers must comply with and demonstrate

    All six Article 5 principles are mandatory legal obligations, and the accountability principle requires controllers to actively demonstrate compliance with all of them.

GDPR Data Protection Principles Flashcards โ€” CSC Study Cards with Answers