Summer Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: dcdisc65

Page: 1 / 5
Total 44 questions
Exam Code: PDPF                Update: Oct 15, 2025
Exam Name: Privacy and Data Protection Foundation

Exin Privacy and Data Protection Foundation PDPF Exam Dumps: Updated Questions & Answers (October 2025)

Question # 1

How does GDPR regulate this specific case?

A woman uses the services of a gym in the city where she lives. Yet she will move to another town. So, she requests the current gym to transfer all her data, exercises, eating plans, physical evaluations, etc. to another gym in the new town.

A.

The current gym is not obliged to answer the holder request, because this could jeopardize the secret of its business.

B.

The current gym should send all her data directly to the new gym.

C.

The gym of the new town should get in contact with the gym and request the data.

D.

The current gym should provide the data to her.

Question # 2

Which condition below allows personal data to be processed legally?

A.

A Data Privacy Impact Assessment (DPIA) should be performed prior to data collection.

B.

Data processing must be previously authorized by the Supervisory Authority.

C.

Holders’ rights must be protected by a privacy policy.

D.

There must be a legitimate basis for data processing.

Question # 3

The GDPR contains several items. Which of these contains mandatory requirements?

A.

Recitals

B.

Articles

Question # 4

According to the GDPR, in what situation must data subjects always be notified of a personal data breach?

A.

When personal data is processed at a facility of the processor that is not located within the borders of the EEA

B.

When personal data is processed by a party that agreed to the draft processing contract but has not yet signed it

C.

When the system on which the personal data is processed is attacked causing damage to its storage devices

D.

When there is a significant probability that the breach will lead to a high risk for the privacy of the data subjects

Question # 5

According to Article.33 of the GDPR the controller shall without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach to the supervisory authority. What is the maximum penalty for non-compliance with this notification obligation?

A.

€ 10.000.000 or 2% of the annual global turnover, whichever is higher

B.

€ 20.000.000 or 4% of the annual global turnover, whichever is higher

C.

Up to € 500.000 with a minimum of € 120.000

D.

Up to € 820.000 with a minimum of € 350.000

Question # 6

The Supervisory Authority is notified whenever an organization intends to process personal data, except for some specific situations. The Supervisory Authority keeps a publicly accessible register of these data processing operations.

What else is a legal obligation of the Supervisory Authority in reaction to such a notification?

A.

To assess compliance with the law in all classes where sensitive personal data is processed

B.

To assess the legitimacy of operations that involve specific risks for the data subjects

C.

To assess the legitimacy of binding contract(s) between the controller and the data processor(s)

D.

To give out a license for the data processing, specifying the types of personal data which are allowed

Question # 7

Subcontracting treatment is regulated by contract or other regulatory act under Union or Member State law, which links the processor to the controller.

What this contract or other regulatory act stipulates?

A.

A process for testing, assessing and regularly evaluating the effectiveness of technical and organizational measures to ensure safe treatment.

B.

The processor assists the driver through technical and organizational measures to enable it to fulfill its obligation to respond to requests from data subjects.

C.

The description of categories of data subjects and categories of personal data

D.

The purpose of data processing

Question # 8

Which of the following options is provided for in the GDPR and can be made by Member States?

A.

Approve national provisions for implementation of GDPR.

B.

Forcing the controller to notify the data subject of a breach.

C.

Audit controller and processor safety processes.

D.

Penalize controllers and processors.

Question # 9

A gentleman has a loan denied by the bank’s system that he has been a customer for many years. He is disgusted, because the loan would make it possible to hold the wedding of his only granddaughter.

He contacts the bank and asks for explanations. He wants to know exactly why his loan was denied and based on what information.

What right is required by the data subject according to the GDPR?

A.

Right to limitation of treatment

B.

Right to rectification

C.

Data subject’s right of access

D.

Right to object and automated individual decision-making

Question # 10

What is the main objective of the “Lifecycle Protection” principle?

A.

All appropriate measures shall be taken to ensure that inaccurate data, taking into account the purposes for which they are processed, are erased or rectified without a delay.

B.

The processing of data must take place in a manner that ensures its security, including protection against unauthorized or unlawful processing and accidental loss, destruction or damage.

C.

Security measures should be in place from the moment data are collected until they are deleted.

D.

Data must be collected for specified, explicit and legitimate purposes and may not be further processed in a manner incompatible with those purposes.

Page: 1 / 5
Total 44 questions

Most Popular Certification Exams

Payment

       

Contact us

dumpscollection live chat

Site Secure

mcafee secure

TESTED 16 Oct 2025