PECB DPO Exam Actual Questions
PECB GDPR - Certified Data Protection Officer (Page 5 )

Updated On: 8-Aug-2026

Scenario 1: MED is a healthcare provider located in Norway. It provides high-quality and affordable healthcare services, including disease prevention, diagnosis, and treatment. Founded in 1995, MED is one of the largest health organizations in the private sector. The company has constantly evolved, as a response to patients' needs. Patients that schedule an appointment in MED's medical centers need to initially provide their personal information, including name and surname, address, phone number, and date of birth. Further checkup or admission requires extra information, including previous medical history and genetic data.
When providing the personal data, patients are informed that the data is used for personalizing their treatments and improving the communication between them and MED's doctors. Medical data of patients, including children, are stored in the database of MED's health information system. MED allows patients who are at least 16 years old to use the system and provide their personal information independently. For children below the age of 16, MED requires consent from the holder of parental responsibility before processing their data. MED uses a cloud-based application that allows patients and doctors to upload and access information. Patients can save all personal medical data, including test results, doctor visits, diagnosis history, and medicine prescription, as well as review and track them at any time. Doctors, on the other hand, can access their patients' data through the application and can add information, as needed. Patients who decide to continue the treatment in another health institution can request by MED to transfer their data. Even if patients decide to continue their treatment in other health institutions, their personal data is still used by MED and patients' requests to stop data processing are rejected. This has been decided from MED's top management in order to save the information of everyone who gets registered in their databases. The company shares medical data with InsHealth, a health insurance company. MED's data helps InsHealth create health insurance plans that meet the needs of individuals and families. MED believes that it is its responsibility to ensure the security and accuracy of the patients' personal data. Thus, based on the identified risks presented by data processing activities, MED has implemented appropriate security measures to ensure that data is securely stored and processed. Since personal data of patients is stored and transmitted over the internet, MED uses encryption to avoid unauthorized processing, accidental loss, or destruction of data. The company has established a security policy to define the levels of protection required for each information and processing activity. MED has communicated the policy and other procedures to the personnel and provided customized training to all personnel to ensure that it is able to use MED's systems needed for data processing. Based on this scenario, answer the following question: If a patient requests MED to permanently erase their data, MED should:

  1. Reject the request since medical history of patients cannot be permanently erased
  2. Erase the personal data if it is no longer needed for its original purpose
  3. Erase the personal data only in case it is needed to comply with a legal obligation

Answer(s): B

Explanation:

The scenario describes a patient's request to permanently erase their data from MED, a healthcare provider. Under the General Data Protection Regulation (GDPR), individuals have the "right to erasure," also known as the "right to be forgotten," as stipulated in Article 17.
MED's current practice of rejecting patients' requests to stop data processing, aiming to "save the information of everyone who gets registered," is a direct violation of GDPR principles, particularly the principles of purpose limitation (Article 5(1)(b)) and storage limitation (Article 5(1)(e)), as well as the data subject's rights.
Answer B, "Erase the personal data if it is no longer needed for its original purpose," correctly aligns with a primary condition for exercising the right to erasure under Article 17(1)(a). This article states that the data subject shall have the right to obtain from the controller the erasure of personal data concerning him or her without undue delay where the personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed.
In the healthcare context, this means that once the patient's treatment has concluded, and any legally mandated retention periods for medical records (which vary by national law, e.g., in Norway) have expired, MED would generally be obliged to erase the data if the patient requests it. MED cannot indefinitely retain personal data based solely on a management decision to "save the information of everyone who gets registered" without a valid legal basis or ongoing necessity for a specific, legitimate purpose.
While there are exceptions to the right to erasure, such as when processing is necessary for reasons of public interest in the area of public health (Article 17(3)(c)) or for compliance with a legal obligation that requires processing by Union or Member State law (Article 17(3)(b)), these are specific conditions. MED must assess if such an exception truly applies to all the data requested for erasure. If a specific legal obligation dictates a retention period for medical records, MED can rely on that. However, once that period expires, or if the data is no longer necessary for providing healthcare to that individual and no other exception applies, the data must be erased upon request.
The fact that MED uses a cloud-based application means it must ensure its cloud service provider can facilitate the secure and complete erasure of data across all systems and backups, demonstrating a robust data lifecycle management process as part of its security measures. MED's sharing of data with InsHealth also implies that if the original purpose for sharing or the lawful basis (e.g., patient consent) ceases, that data should also be erased from InsHealth's systems.
In summary, MED cannot simply reject all erasure requests. It must evaluate each request against the conditions of Article 17, particularly whether the data is still necessary for the original purposes for which it was collected or whether a specific legal obligation or other legitimate exception applies. If not, the data must be erased.
Authoritative Links:
GDPR Article 17 - Right to erasure ('right to be forgotten'): https://gdpr-info.eu/art-17-gdpr/ GDPR Article 5 - Principles relating to processing of personal data: https://gdpr-info.eu/art-5-gdpr/



Based on scenario 1, is the processing of children's personal data performed by MED in compliance with the GDPR?

  1. No, the processing of personal data of children below the age of 16 years is not in compliance with the GDPR, even if parental consent is provided
  2. Yes, the processing of children's personal data below the age of 16 years with parental consent is in compliance with the GDPR
  3. No, MED must obtain explicit consent from the child, regardless of parental consent, for the processing to be in compliance with the GDPR

Answer(s): B

Explanation:

The processing of children's personal data by MED is indeed in compliance with the GDPR when parental consent is provided for those under 16 years of age. This is explicitly stipulated in Article 8, paragraph 1 of the General Data Protection Regulation (GDPR).
GDPR Article 8, entitled "Conditions applicable to child's consent in relation to information society services," states that for information society services offered directly to a child, the processing of a child's personal data is lawful where the child is at least 16 years old. If the child is younger than 16 years, such processing is lawful only if and to the extent that consent is given or authorised by the holder of parental responsibility over the child. Member States have the discretion to provide for a lower age, provided that such lower age is not below 13 years, but the default age for direct child consent is 16.
Given that MED is processing the personal data of children below the age of 16 and has obtained parental consent, this action directly adheres to the requirements set forth in Article 8(1) of the GDPR. Therefore, the processing is lawful.
Option A is incorrect because parental consent is explicitly recognized as the valid legal basis for processing children's data when they are below the age of digital consent (typically 16). Option C is incorrect because the GDPR does not mandate explicit consent from the child themselves when they are under the age of 16; rather, it shifts the responsibility for consent to the parent or guardian.
Cloud computing concepts play a vital role in implementing such GDPR compliance. Cloud-based Consent Management Platforms (CMPs) enable organisations like MED to effectively capture, record, and manage parental consent, providing a verifiable and auditable trail as required by the GDPR's accountability principle. Identity and Access Management (IAM) systems deployed in the cloud can facilitate robust age verification mechanisms, helping to determine accurately when parental consent is necessary. Furthermore, secure cloud storage and processing services become critical for protecting children's personal data, ensuring that encryption, access controls, and other technical and organisational measures are in place to meet GDPR's security requirements (Article 32). Cloud architectures can also be designed to support data minimization and purpose limitation , ensuring that only data relevant to the purpose for which parental consent was obtained is collected and processed.
Authoritative Links:
GDPR Article 8 - Conditions applicable to child’s consent in relation to information society services: https://gdpr-info.eu/art-8-gdpr/ Official text of the GDPR (Regulation (EU) 2016/679): https://eur-lex.europa.eu/legal-content/EN/TXT/? uri=CELEX%3A32016R0679



Considering the nature of data processing activities described in scenario 1, is GDPR applicable to MED?

  1. Yes, the GDPR is applicable to MED due to its processing activities involving personal information
  2. Yes, MED uses cloud-based software to store and process health-related information necessitates compliance with the GDFR's data protection requirements
  3. No, MED's activities include healthcare services within one of the four EFTA states, which do not fall under the scope of the GDPR

Answer(s): A

Explanation:

The GDPR is undeniably applicable to MED primarily because its core activities involve the processing of "personal data," specifically sensitive health-related information. This is the fundamental trigger for GDPR applicability. Personal data refers to any information relating to an identified or identifiable natural person, and health data falls under the "special categories of personal data" (Article 9), which receive heightened protection under the Regulation.
As a healthcare provider, MED would function as a data controller, determining the purposes and means of processing patients' health records, medical histories, and other identifying information crucial for delivering services. Even if MED operates within an EFTA state, the GDPR's broad territorial scope often applies. For instance, EEA EFTA states (Iceland, Liechtenstein, Norway) have incorporated GDPR into their national laws. Furthermore, if MED offers services to individuals residing in the EU/EEA, or monitors their behavior, the extraterritorial provisions of GDPR (Article 3(2)) would mandate compliance, regardless of MED's physical establishment.
While MED's use of cloud-based software (as suggested in option B) is a relevant aspect, it is not the primary reason for GDPR applicability; rather, it's a method of processing personal data that must comply with GDPR. The use of cloud services introduces specific responsibilities for MED as the controller, such as ensuring data processing agreements (Article 28) are in place with cloud providers (who act as processors). These agreements must specify security measures (Article 32), data handling procedures, and accountability mechanisms, particularly when dealing with special categories of data. Cloud computing, whether IaaS, PaaS, or SaaS, still requires MED to uphold its responsibilities for data protection, security, and data subject rights. The choice of storage or processing technology doesn't negate the need for compliance; instead, it shapes the specific technical and organizational measures required. Therefore, the processing of personal information itself, especially sensitive health data, forms the foundational basis for GDPR's applicability to MED.
For further research:
Official GDPR Text (Article 3 - Territorial Scope, Article 9 - Special Categories of Data): https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32016R0679 European Data Protection Board (EDPB) Guidelines: https://edpb.europa.eu/our-work-tools/documents/guidance_en European Commission - What is personal data?: https://ec.europa.eu/info/law/law-topic/data-protection/reform/what-personal-data_en



Based on scenario 1, MED shares their patients' personal data with a health insurance company. Does MED comply with the purpose limitation principle?

  1. Yes, personal data may be used for purposes in the public interest or statistical purposes in accordance with Article 89 of GDPR
  2. Yes, using personal data for creating health insurance plans is within the scope of the data collection purpose
  3. No, personal data should be collected for specified, explicit, and legitimate purposes in accordance with Article 5 of GDPR

Answer(s): C

Explanation:

The purpose limitation principle, a cornerstone of the GDPR, is outlined in Article 5(1)(b), which mandates that personal data must be collected for specified, explicit, and legitimate purposes and not further processed in a manner that is incompatible with those initial purposes. In this scenario, MED, as a healthcare provider, would primarily collect patients' personal data for the explicit purpose of delivering medical care, treatment, and associated administrative functions like billing for services rendered.
Sharing this sensitive health data with a health insurance company for the distinct purpose of "creating health insurance plans" constitutes further processing. This secondary processing is generally considered incompatible with the original, primary purpose of providing direct healthcare. Unless MED explicitly informed patients about this specific secondary use at the time of data collection and obtained their explicit, informed consent for this particular sharing, it represents a violation of the principle. For special categories of personal data, such as health information, Article 9 of the GDPR requires a stricter condition for processing, often explicit consent, alongside a lawful basis under Article 6.
Simply providing medical care does not inherently grant the healthcare provider permission to share patient data with third-party insurance companies for their commercial product development or general business strategies. Such data sharing often extends beyond what the data subject would reasonably expect based on the initial context of data collection. Option A is incorrect because processing for "public interest or statistical purposes" under Article 89 refers to specific research or archival activities, not commercial data sharing with a private company for plan creation. Option B is also incorrect, as "creating health insurance plans" serves a distinct commercial purpose of the insurance company, which typically falls outside the scope of MED's primary function of providing medical treatment.
Even when MED utilizes cloud computing services for data storage and processing, the ultimate responsibility for adhering to GDPR principles like purpose limitation remains squarely with MED as the data controller. Cloud platforms offer robust access controls, encryption, and auditing capabilities; however, it is MED's duty to configure and enforce these features to ensure data is only accessed and processed for its intended, specified purposes. Effective data governance frameworks, particularly within cloud environments, must ensure that any data sharing mechanisms, whether via APIs or secure file transfers, are compliant with the initially defined purposes and supported by a valid lawful basis. Without explicit consent or another clearly defined and documented lawful basis specifically for sharing data with an insurance company to create health plans, MED's actions are non-compliant with the purpose limitation principle.
Authoritative Links for Further Research:
GDPR Article 5 – Principles relating to processing of personal data: https://gdpr-info.eu/art-5-gdpr/ GDPR Article 6 – Lawfulness of processing: https://gdpr-info.eu/art-6-gdpr/ GDPR Article 9 – Processing of special categories of personal data: https://gdpr-info.eu/art-9-gdpr/ EDPB Guidelines 05/2020 on consent under Regulation 2016/679 (updated version): https://edpb.europa.eu/our-work-tools/our-documents/guidelines/guidelines-052020-consent-under-regulation-2016679_en ICO – Guide to GDPR – Lawfulness, fairness and transparency: https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/principles/



Based on scenario 1, which data subject right is NOT guaranteed by MED?

  1. Right to be informed
  2. Right to restriction of processing
  3. Right to data portability

Answer(s): B

Explanation:

The data subject right NOT guaranteed by MED (Medical Electronic Data system) is the Right to restriction of processing (Article 18 GDPR) .
MED, as a system handling sensitive health data, operates under specific legal and ethical frameworks that often override an individual's right to restrict processing. Medical data, classified as "special categories of personal data" under Article 9 GDPR, can be processed without explicit consent if necessary for the provision of health or social care, medical diagnosis, or the management of health systems, based on Union or Member State law (Article 9(2)(h)).
The right to restriction implies that personal data can be stored but not further processed under certain conditions, such as when the accuracy of the data is contested or processing is unlawful. However, in a healthcare context, restricting access to or processing of a patient's medical records could severely compromise patient safety, continuity of care, and the ability of healthcare professionals to provide effective treatment. For instance, a doctor requires a complete and up-to-date medical history to make informed decisions, especially in emergencies.
Furthermore, healthcare providers are often subject to legal obligations to maintain comprehensive and accessible patient records for specific periods, for audit purposes, and for public health reporting. Restricting processing could conflict with these statutory duties.
While cloud computing concepts like data isolation or access control policies could technically facilitate restriction, the fundamental legal and functional necessity of continuous data processing in healthcare often takes precedence, relying on the derogations specified in
GDPR. Cloud-based EHRs are designed for real-time access and interoperability, making a "pause" on processing inherently challenging without risking critical care outcomes.
In contrast, the Right to be informed (Articles 13 & 14 GDPR) is a fundamental transparency requirement that healthcare providers must always uphold. Patients must be fully informed about how their health data is collected, used, and stored. Similarly, the Right to data portability (Article 20 GDPR) is increasingly crucial and often guaranteed by modern medical systems like MED. This right enables individuals to receive their personal data in a structured, commonly used, machine-readable format and transmit it to another controller, facilitating patient choice and interoperability in healthcare. Therefore, while MED would guarantee transparency and data transferability, the critical nature of health data processing limits the practical and lawful application of the right to restriction.
Authoritative Links for Further Research:
GDPR Official Text: https://gdpr-info.eu/ (Specifically Articles 9, 13, 14, 18, 20) European Data Protection Board (EDPB) Guidelines: The EDPB issues guidelines on various GDPR topics, including data subject rights, which are highly authoritative.
While specific guidance on the right to restriction in health might be embedded, general guidelines on Article 18 are relevant: https://edpb.europa.eu/our-work-tools/documents/guidelines/guidelines-12019-article-20-right-data-portability_en (See also other guidelines on rights) ENISA (European Union Agency for Cybersecurity) on Cloud Security for Health Data: While not directly about GDPR rights, ENISA provides insights into securing health data in cloud environments, which informs the technical feasibility of managing these rights: https://www.enisa.europa.eu/news/enisa-news/cloud-security-for-the-health-sector



Scenario 2: Soyled is a retail company that sells a wide range of electronic products from top European brands. It primarily sells its products in its online platforms (which include customer reviews and ratings), despite using physical stores since 2015. Soyled's website and mobile app are used by millions of customers. Soyled has employed various solutions to create a customer-focused ecosystem and facilitate growth. Soyled uses customer relationship management (CRM) software to analyze user data and administer the interaction with customers. The software allows the company to store customer information, identify sales opportunities, and manage marketing campaigns. It automatically obtains information about each user's IP address and web browser cookies. Soyled also uses the software to collect behavioral data, such as users' repeated actions and mouse movement information. Customers must create an account to buy from Soyled's online platforms. To do so, they fill out a standard sign-up form of three mandatory boxes (name, surname, email address) and a non-mandatory one (phone number).
When the user clicks the email address box, a pop-up message appears as follows: "Soyled needs your email address to grant you access to your account and contact you about any changes related to your account and our website. For further information, please read our privacy policy." When the user clicks the phone number box, the following message appears: "Soyled may use your phone number to provide text updates on the order status. The phone number may also be used by the shipping courier." Once the personal data is provided, customers create a username and password, which are used to access Soyled's website or app.
When customers want to make a purchase, they are also required to provide their bank account details.
When the user finally creates the account, the following message appears: "Soyled collects only the personal data it needs for the following purposes: processing orders, managing accounts, and personalizing customers' experience. The collected data is shared with our network and used for marketing purposes." Soyled uses personal data to promote sales and its brand. If a user decides to close the account, the personal data is still used for marketing purposes only. Last month, the company received an email from John, a customer, claiming that his personal data was being used for purposes other than those specified by the company. According to the email, Soyled was using the data for direct marketing purposes. John requested details on how his personal data was collected, stored, and processed. Based on this scenario, answer the following question: When completing the sign-up form, the user gets a notification about the purpose for which the company collects their email address. Is Soyled required by the GDPR to do so?

  1. Yes, users must be informed of the purpose of collecting their personal data
  2. No, Soyled should provide this information only when requested by users
  3. No, Soyled only needs to inform users about how their data is collected, stored, or processed

Answer(s): A

Explanation:

Yes, Soyled is unequivocally required by the GDPR to inform users about the purpose of collecting their personal data, including their email address, at the point of collection. This obligation stems directly from the GDPR's foundational principles of lawfulness, fairness, and transparency, outlined in Article 5(1)(a).
More specifically, Article 13 of the GDPR, titled "Information to be provided where personal data are collected from the data subject," mandates that data controllers must provide specific information to individuals when personal data is obtained from them. Article 13(1)(c) explicitly states that this information must include "the purposes of the processing for which the personal data are intended as well as the legal basis for the processing."
By displaying the pop-up message – "Soyled needs your email address to grant you access to your account and contact you about any changes related to your account and our website" – Soyled is fulfilling this crucial transparency requirement. This ensures that users are fully aware of why their email address is being requested and how it will be utilized.
This also aligns with the principle of purpose limitation (Article 5(1)(b)), which dictates that personal data shall be collected for specified, explicit, and legitimate purposes and not further processed in a manner that is incompatible with those purposes. Informing the data subject of these purposes at the time of collection is essential for demonstrating compliance with this principle. Without such explicit communication, the processing of personal data would lack the necessary transparency and fairness, potentially violating the data subject's rights and the GDPR's core objectives. Therefore, Soyled's action is a mandatory step for GDPR compliance.
Authoritative Links for Further Research:
GDPR Article 5 (Principles relating to processing of personal data): https://gdpr-info.eu/art-5-gdpr/ GDPR Article 13 (Information to be provided where personal data are collected from the data subject): https://gdpr-info.eu/art-13-gdpr/



The GDPR indicates that the processing of personal data should be based on a legal contract with the data subject. Based on scenario 2, has Soyled fulfilled this requirement?

  1. Yes, data subjects are informed about the purpose of collecting the email address and phone number before the data is collected
  2. Yes, once the account is created, Soyled informs its customers that their personal data will be shared with the network
  3. No, data subjects are informed that the personal data will be shared with Soyled's network only after the personal data is collected

Answer(s): C

Explanation:

Answer C is correct because Soyled fails to adhere to a fundamental principle of the General Data Protection Regulation (GDPR): transparency and the provision of information to data subjects at the point of data collection. GDPR Article 5(1)(a) mandates that personal data must be processed lawfully, fairly, and in a transparent manner in relation to the data subject. Furthermore, Article 13 specifies that the data controller must provide the data subject with crucial information, including the recipients or categories of recipients of the personal data, at the time the data is obtained.
Informing data subjects that their personal data will be shared with Soyled's network only after the data has been collected (as stated in option C) directly contravenes this requirement. This timing means the data subject did not possess full awareness of how their data would be processed, particularly regarding its disclosure to third parties or an interconnected network, before deciding to provide it. Such a practice undermines the data subject's ability to make an informed decision, thereby compromising the fairness and lawfulness of the processing.
While the question mentions processing based on a "legal contract," even under Article 6(1)(b) (performance of a contract) as a lawful basis, the principle of transparency still applies. For processing to be necessary for a contract, and thus lawful, the data subject must be clearly informed about all essential processing activities, including data sharing, before entering into the contract and providing their personal data. Informing them post-collection implies that a key aspect of the data processing was not part of the initial agreement or transparently communicated, potentially invalidating the reliance on the contract for that specific processing purpose.
Options A and B are incorrect because they imply or state that information is provided, but they either miss the critical aspect of when the information about sharing with the network is provided or suggest it's provided too late. Option A focuses on the initial purpose of collecting email/phone but doesn't explicitly confirm the sharing with the network was included in this initial disclosure. Option B, stating "once the account is created," unequivocally indicates that the crucial information about data sharing is provided after the initial data collection and the establishment of the relationship, which is insufficient under GDPR.
In a modern data processing landscape, where "Soyled's network" often implies data sharing across various cloud-based services, affiliates, or partners, the responsibility of the data controller (Soyled) to communicate the entire data flow and intended recipients transparently is paramount. Regardless of whether the underlying infrastructure uses cloud computing services, the data controller remains accountable for informing data subjects upfront about all processing activities, ensuring their consent is informed or that other lawful bases are met with adequate transparency.
The lack of upfront transparency regarding data sharing violates the core principles of data protection and can lead to non-compliance, potential fines, and a breach of trust with data subjects.
Authoritative Links for Further Research:
GDPR Article 5 – Principles relating to processing of personal data: https://gdpr-info.eu/art-5-gdpr/ GDPR Article 6 – Lawfulness of processing: https://gdpr-info.eu/art-6-gdpr/ GDPR Article 13 – Information to be provided where personal data are collected from the data subject: https://gdpr-info.eu/art-13-gdpr/ ICO Guidance on Lawful Basis for Processing (specifically Contract): https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection-regulation-gdpr/lawful-basis-for-processing/contract/ EDPB Guidelines on Transparency under Regulation 2016/679: https://edpb.europa.eu/our-work-tools/documents/guidelines/edpb-guidelines-072020-transparency-under-regulation_en



Based on scenario 2, Soyled only has three mandatory fields in its sign-up form. On which principle is this decision based?

  1. Lawfulness, fairness, and transparency
  2. Purpose limitation
  3. Data minimization

Answer(s): C

Explanation:

Soyled's decision to include only three mandatory fields in its sign-up form is a direct application of the Data Minimization principle, as outlined in Article 5(1)(c) of the General Data Protection Regulation (GDPR). This principle mandates that personal data collected must be adequate, relevant, and limited to what is necessary in relation to the specific purposes for which it is processed. By restricting mandatory fields to the absolute minimum, Soyled ensures it is not gathering superfluous data that is not essential for user registration or the primary service provided.
This approach significantly reduces the potential risks associated with data processing. Less data means a smaller attack surface for cyber threats and a diminished impact in the event of a data breach. For organizations leveraging cloud computing services, data minimization is a crucial aspect of security by design.
When data is stored and processed in the cloud, be it IaaS, PaaS, or SaaS, collecting only necessary information reduces the volume of sensitive data residing on third-party infrastructure. This simplifies data governance, lowers potential storage costs, and strengthens the organization's position within the shared responsibility model by minimizing its own data controller liability.
While "Lawfulness, fairness, and transparency" (Article 5(1)(a)) is a foundational principle for all data processing, it addresses the legal basis, ethical handling, and clear communication with data subjects, rather than the quantity of data collected. Similarly, "Purpose limitation" (Article 5(1)(b)) requires data to be collected for specified, explicit, and legitimate purposes. Although closely related—you minimize data for a defined purpose—the act of limiting the number of mandatory fields specifically demonstrates adherence to data minimization. Purpose limitation dictates why data is needed, whereas data minimization dictates how little data is collected to achieve that "why." Therefore, Soyled's choice directly reflects a commitment to collecting only what is absolutely essential, making data minimization the precise principle at play.
Authoritative Links for Further Research:
GDPR Article 5 - Principles relating to processing of personal data: https://gdpr-info.eu/art-5-gdpr/ Information Commissioner's Office (ICO) - Data minimisation: https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection-regulation-gdpr/principles/data-minimisation/ European Data Protection Board (EDPB) - Guidelines on Data Protection by Design and by Default: (Often referenced for practical application of principles like data minimization) https://edpb.europa.eu/our-work-tools/our-documents/guidelines/edpb-guidelines-042021-data-protection-design-and-default_en



Viewing page 5 of 11
Viewing questions 33 - 40 out of 80 questions


Post your Comments and Discuss PECB DPO exam prep with other Community members:

AI Tutor AI Tutor 👋 I’m here to help!