20 questions
1. Is data considered personal data if it identifies a person only when combined with other data?
2. Is data considered personal data if it identifies a person only when combined with other data?
3. Which factor determines whether a corporate email account is personal data?
4. Distributing a business card most accurately implies:
5. Which practice is a violation even if a general consent exists?
6. Which is the strongest indicator that data is 'indirectly identifiable'?
7. When does retention most clearly violate PDPL principles?
8. Which is the most accurate description of data minimization?
9. A cross-border transfer is most clearly unlawful when:
10. Which practice undermines transparency most directly?
11. Who bears primary accountability for PDPL compliance in a processing arrangement?
12. Which scenario most clearly constitutes unfair processing?
13. Breach notification to the data subject is generally not required when:
14. Which organizational setup most undermines DPO independence?
15. A 'related purpose' is best interpreted as:
16. Which item alone is least sufficient as evidence of compliance during an audit?
17. Work email such as 46633@company.com is personal data when:
18. Which is a high-risk 'paper compliance' indicator?
19. Consent is most valid when it is:
20. Records of processing activities primarily support: