Scenario:
PickFoodis an onlinefood delivery servicethat allows customers to order foodonlineand pay bycredit card.
Thepayment serviceis provided byPaySmart, which processes the transactions.
Question:
According toArticle 30 of GDPR, whattype of information should PaySmart NOT maintainwhen recording online transaction processing activity?
A. Alist of customers' transaction amounts and items purchased.
B. Transfers of personal data tothird-party payment processors.
C. Theexpected time for personal data erasure.
D. Thegeneral descriptionof technical data protection measures.
正解:A
解説: (Pass4Test メンバーにのみ表示されます)
質問 2:
Scenario 8:MA store is an online clothing retailer founded in 2010. They provide quality products at a reasonable cost. One thing that differentiates MA store from other online shopping sites is their excellent customer service.
MA store follows a customer-centered business approach. They have created a user-friendly website with well-organized content that is accessible to everyone. Through innovative ideas and services, MA store offers a seamless user experience for visitors while also attracting new customers. When visiting the website, customers can filter their search results by price, size, customer reviews, and other features. One of MA store's strategies for providing, personalizing, and improving its products is data analytics. MA store tracks and analyzes the user actions on its website so it can create customized experience for visitors.
In order to understand their target audience, MA store analyzes shopping preferences of its customers based on their purchase history. The purchase history includes the product that was bought, shipping updates, and payment details. Clients' personal data and other information related to MA store products included in the purchase history are stored in separate databases. Personal information, such as clients' address or payment details, are encrypted using a public key. When analyzing the shopping preferences of customers, employees access only the information about the product while the identity of customers is removed from the data set and replaced with a common value, ensuring that customer identities are protected and cannot be retrieved.
Last year, MA store announced that they suffered a personal data breach where personal data of clients were leaked. The personal data breach was caused by an SQL injection attack which targeted MA store's web application. The SQL injection was successful since no parameterized queries wereused.
Based on this scenario, answer the following question:
What did MA store use when storing clients' address and payment details in its system?
A. Pseudonymization
B. Data erasure and disposal
C. Plain text storage
正解:A
解説: (Pass4Test メンバーにのみ表示されます)
質問 3:
Scenario:
Bankbiois a financial institution that handlespersonal dataof its customers. Itsdata processing activities involve processingthat is necessary for thelegitimate interestspursued by the institution. In such cases, Bankbio processes personal datawithout obtaining consent from data subjects.
Question:
Is the data processinglawful under GDPR?
A. Yes, processing is lawful when it is necessary for thelegitimate interestspursued by the controller, except where such interests are overridden by the interests of fundamental rights.
B. No, financial institutionsmust always obtain explicit consentbefore processing personal data.
C. Yes, GDPR allows the processing of personal data for thelegitimate interest pursued by the controller or by a third party in all cases.
D. No, the processing is lawfulonly if the data subject has given explicit consentto the processing of personal data for the specified purpose.
正解:A
解説: (Pass4Test メンバーにのみ表示されます)
質問 4:
Scenario:
A financial institution collectsbiometric data of its clients, such asface recognition, to support apayment authentication processthat they recently developed. The institution ensures thatdata subjects provide explicit consentfor the processing of theirbiometric datafor this specific purpose.
Question:
Based on this scenario, should theDPO advise the organization to conduct a DPIA (Data Protection Impact Assessment)?
A. No, becauseexplicit consenthas already been obtained from the data subjects.
B. Yes, because biometric data is consideredspecial category personal data, and its processing is likely to involvehigh risk.
C. No, because DPIAs areonly requiredwhen processing personal dataon a large scale, which is not specified in this case.
D. Yes, but only if the biometric data is storedfor more than five years.
正解:B
解説: (Pass4Test メンバーにのみ表示されます)
質問 5:
Scenario:
Amarketing companydiscovers that anunauthorized party accessed its customer database, exposing5,000 recordscontainingnames, email addresses, and phone numbers. The breach occurred due to a misconfigured server.
Question:
To comply withGDPR, whichinformation must the company includein itsnotification to the supervisory authority?
A. Theapproximate number of data subjectsand records affected.
B. Adescription of the natureof the personal data breach.
C. Both A and B.
D. Theidentity of the attackerand their potential motive.
正解:C
解説: (Pass4Test メンバーにのみ表示されます)
1106 お客様のコメント





大森** -
内容もしっかりしているし、かなりコスパが高いです。GDPR知識としてこれだけの情報を持っていれば、仕事にも必ず役に立つ。