โ† All PLC Flashcard Decks

Consent Management & User Rights Flashcards

9 cards from real PLC practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 9 Consent Management & User Rights flashcards as text
  1. What makes consent valid under GDPR?

    Answer: Freely given and informed

    Under GDPR, valid consent must be freely given, specific, informed, and unambiguous. This means individuals must have a genuine choice without pressure, understand exactly what they are consenting to, and provide a clear affirmative action. Bundled consent or assumed consent is generally not considered valid, ensuring the individual's true intent.

  2. Which right allows individuals to request a copy of their personal data?

    Answer: Right to access

    The Right to Access allows individuals to obtain confirmation as to whether their personal data is being processed, and if so, to access that data and supplementary information. This empowers individuals to understand what information an organization holds about them and how it is being used. It is a fundamental right for data subjects to maintain control over their personal information.

  3. Which user right involves correction of inaccurate personal data?

    Answer: Right to rectification

    The Right to Rectification allows individuals to request that inaccurate personal data concerning them be corrected without undue delay. If the data is incomplete, they also have the right to have it completed, taking into account the purposes of the processing. This ensures the accuracy and fairness of personal information, preventing harm from incorrect data.

  4. Which principle gives users the ability to withdraw consent at any time?

    Answer: Right to withdraw consent

    A fundamental aspect of valid consent under privacy laws like GDPR is that individuals must have the right to withdraw their consent at any time. This means that if they initially agreed to data processing, they can later revoke that permission, and the organization must cease processing their data based on that consent. This ensures ongoing control over personal information.

  5. What is required before processing personal data under consent basis?

    Answer: Explicit opt-in

    For consent to be valid under GDPR, it generally requires an explicit opt-in, meaning individuals must take a clear, affirmative action to indicate their agreement. Pre-checked boxes, passive browsing, or implied consent are typically not sufficient. This ensures that consent is unambiguous and genuinely reflects the individual's informed choice, giving them true control.

  6. Which right allows individuals to request deletion of their data?

    Answer: Right to erasure

    The Right to Erasure, often called the 'Right to be Forgotten,' allows individuals to request the deletion or removal of their personal data where there is no compelling reason for its continued processing. This right applies in specific circumstances, such as when the data is no longer necessary for the purpose for which it was collected or when consent is withdrawn. It empowers individuals to control their digital footprint.

  7. Consent must be as easy to withdraw as it was to:

    Answer: Provide

    A key requirement for valid consent under GDPR is that it must be as easy for an individual to withdraw their consent as it was to provide it. This ensures that individuals retain control over their personal data and are not trapped into ongoing processing once they have given permission. It prevents organizations from making withdrawal unnecessarily difficult, upholding user autonomy.

  8. Which right involves receiving personal data in a machine-readable format?

    Answer: Right to data portability

    The Right to Data Portability allows individuals to obtain and reuse their personal data for their own purposes across different services. It enables them to receive their personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another data controller without hindrance. This promotes competition and user control over their digital footprint.

  9. Which document typically outlines how and why user data is collected and used?

    Answer: Privacy policy

    A privacy policy is a legal document that explicitly informs users about how an organization collects, uses, stores, and protects their personal data. It details the types of data gathered, the purposes for collection, data sharing practices, and user rights regarding their information. This transparency is crucial for compliance with data protection laws and building user trust.