Question 1
What is personal data under GDPR?
Below is a complete list of real practice questions you may be asked during the GDPR Basics: Key Definitions, Principles, Rights, and Lawful Bases. Try answering each one yourself before checking your knowledge. If you find questions you don’t know, you can study them using our interactive spaced-repetition flashcards that repeat what you forget.
Study these questions using spaced-repetition flashcards that focus on the questions you miss.
Start studying free →First try to answer each question yourself. After attempting a few, practice recalling the answers using the interactive flashcard study mode . Actively recalling the answer before revealing it helps long-term memory much more than rereading a list.
What is personal data under GDPR?
Who is a data controller?
Who is a data processor?
What is a data subject?
What is processing under GDPR?
What is special category data?
What does pseudonymization mean?
What does anonymization mean?
What is a data breach?
What is a profiling activity?
What is explicit consent?
What is a supervisory authority?
What are the six GDPR principles?
What does lawfulness, fairness, transparency mean?
What is purpose limitation?
Turn these into interactive flashcards and track your progress automatically.
Practice with flashcards →What is data minimization?
What is the accuracy principle?
What is storage limitation?
What is integrity and confidentiality?
What is the accountability principle?
Why must processing be transparent?
How does purpose limitation affect data reuse?
What makes processing fair?
How long should you keep personal data?
What is the right to be informed?
What is the right of access?
What is the right to rectification?
What is the right to erasure?
What is the right to restrict processing?
What is the right to data portability?
Turn these into interactive flashcards and track your progress automatically.
Practice with flashcards →What is the right to object?
What are rights regarding automated decision-making?
How long do you have to respond to rights requests?
Can you charge for subject access requests?
When can you refuse a rights request?
What must a privacy notice include?
What are the six lawful bases for processing?
What is valid consent under GDPR?
When is consent not freely given?
What is the contract basis?
What is the legal obligation basis?
What is the vital interests basis?
What is the public task basis?
What is the legitimate interests basis?
What is a Legitimate Interests Assessment?
Turn these into interactive flashcards and track your progress automatically.
Practice with flashcards →Can you switch lawful bases?
Must consent be documented?
When should you use consent as basis?
When must you report a breach to authorities?
When must you notify individuals of a breach?
What should a breach notification include?
Must you keep records of breaches?
What counts as becoming aware of a breach?
What are examples of high-risk breaches?
Who is responsible for breach notifications?
What mitigation steps should you take?
What if you can't report within 72 hours?
What's a controller-to-controller breach?
Can you avoid notifying individuals?
What's a breach response plan?
Turn these into interactive flashcards and track your progress automatically.
Practice with flashcards →When must you appoint a DPO?
What are a DPO's main tasks?
Can a DPO be an existing employee?
What qualifications should a DPO have?
Can multiple organizations share a DPO?
Must you publish DPO contact details?
Can you dismiss a DPO?
What resources must you provide to DPO?
Can a DPO outsource work?
Who reports to the DPO?
Can a DPO be a lawyer?
What's the difference between DPO and privacy officer?
What is privacy by design?
What is privacy by default?
What is a Data Protection Impact Assessment?
Turn these into interactive flashcards and track your progress automatically.
Practice with flashcards →When must you conduct a DPIA?
What should a DPIA include?
Who should be consulted in a DPIA?
When should you consult supervisory authority?
What are appropriate technical measures?
What are appropriate organizational measures?
Should you review DPIAs regularly?
What's the screening list for DPIAs?
Can you use a single DPIA for multiple projects?
What is an international transfer?
What is an adequacy decision?
What are Standard Contractual Clauses?
What are Binding Corporate Rules?
Can you transfer data based on consent?
What is a Transfer Impact Assessment?
Turn these into interactive flashcards and track your progress automatically.
Practice with flashcards →Which countries have adequacy decisions?
What happened to Privacy Shield?
Does storing data in EU avoid transfer issues?
What are supplementary measures?
Can you transfer for contract performance?
What about transfers for legal claims?
What are GDPR fines?
What determines fine amount?
Can individuals claim compensation?
Can supervisory authorities issue warnings?
Who enforces GDPR?
What is the one-stop-shop mechanism?
Can authorities conduct audits?
Can processing be temporarily banned?
How do individuals lodge complaints?
Turn these into interactive flashcards and track your progress automatically.
Practice with flashcards →Are there criminal penalties?
What's liability for joint controllers?
What's liability for processors?
What are Records of Processing Activities?
What must records of processing include?
Do small businesses need GDPR compliance?
What's a processor agreement?
What must a processor agreement include?
Can processors use sub-processors?
What's the territorial scope of GDPR?
Do I need a representative?
What's a retention schedule?
Should you train employees on GDPR?
What policies should you have?
How often should you review compliance?
Memorizing questions isn’t enough. Our system repeats the questions you struggle with until you reliably remember them — the same learning method used by language apps.
This page provides the complete question reference. For real practice, use the flashcard training mode to test yourself until you can consistently answer correctly without looking.
Start studying now (free)