Question 61

You are the new Data Protection Officer for your company and have to determine whether the company has implemented appropriate technical and organizational measures as required by Article 32 of the GDPR. Which of the following would be the most important to consider when trying to determine this?
  • Question 62

    What term BEST describes the European model for data protection?
  • Question 63

    Which statement is correct when considering the right to privacy under Article 8 of the European Convention on Human Rights (ECHR)?
  • Question 64

    How does the GDPR now define "processing"?
  • Question 65

    Company X has entrusted the processing of their payroll data to Provider Y.
    Provider Y stores this encrypted data on its server. The IT department of Provider Y finds out that someone managed to hack into the system and take a copy of the data from its server. In this scenario, whom does Provider Y have the obligation to notify?