[2024年06月]更新のBCS PDP9試験一発合格保証! [Q11-Q35]

Share

[2024年06月]更新のBCS PDP9試験一発合格保証!

完全版PDP9練習テスト42独特な解答と解釈が待ってます!今すぐ取得せよ!

質問 # 11
Of the following options which is NOT a purpose of carrying out a Data Protection Impact Assessment (DPIA)?

  • A. It is necessary to fulfil the requirement that all DPIAs are submitted to the ICO
  • B. It assists in identifying the main risks that may exist in any use of data, so that they can be mitigated
  • C. It is key to the accountability element of the GDPR.
  • D. It fulfils a requirement that data protection is carried out by design and default.

正解:A

解説:
Explanation
A DPIA is not required to fulfil the requirement that all DPIAs are submitted to the ICO, because this is not a requirement under the GDPR. The GDPR only requires that the controller consults the ICO before carrying out processing that is likely to result in a highrisk to individuals, if the controller cannot mitigate that risk. This means that not all DPIAs need to be submitted to the ICO, only those that identify a high residual risk that cannot be reduced. The other options are valid purposes of carrying out a DPIA, as they help the controller to comply with the GDPR, ensure data protection by design and by default, and identify and mitigate the main risks to individuals' rights and freedoms. References:
* Article 35 and 36 of the GDPR3
* ICO guidance on DPIAs5


質問 # 12
What are Information Society Services'? Select the INCORRECT answer

  • A. Information services provided by non-profit or government organisations with no remuneration
  • B. Business to business online networking sites
  • C. A service provided for remuneration, by electronic means, at distance to an individual that has requested it.
  • D. An electronic information service provided to individuals but paid for solely by advertising

正解:A

解説:
Explanation
Information society services (ISS) are defined in Article 4(25) of the UK GDPR as "any service normally provided for remuneration, at a distance, by electronic means and at the individual request of a recipient of services". This means that ISS are online services that are paid for, either by the user or by another source of income, such as advertising or sponsorship, and that are provided without the parties being physically present, using electronic equipment for the transmission and reception of data, and upon the request of the user.
Examples of ISS include apps, programs, websites, search engines, social media platforms, online marketplaces, content streaming services, online games, and any other online services that offer goods or services to users over the internet. Therefore, options A, B and C are correct examples of ISS, as they meet the criteria of the definition. However, option D is not a correct example of ISS, as it does not involve any remuneration for the service provider. Information services provided by non-profit or government organisations with no remuneration are not considered ISS under the UK GDPR, unless they compete with other ISS on the market. References:
* UK GDPR, Article 4(25)4
* Services covered by this code5


質問 # 13
What is the basis of the accountability and data governance obligation (Article 5 (2) of the GDPR)?

  • A. Processors have overarching responsibility to ensure their processing is compliant
  • B. Controllers and Processors each have a responsibility to conduct legitimate interests balancing tests before processing data for direct marketing
  • C. The controller shall be responsible for. and be able to demonstrate compliance with the data protection principles.
  • D. The controller shall appoint a DPO before carrying out large scale processing

正解:C

解説:
Explanation
Article 5(2) of the GDPR introduces the principle of accountability, which requires that the controller is responsible for, and be able to demonstrate compliance with, the data protection principles set out in Article
5(1). These principles are: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and data protection by design and by default. The controller must implement appropriate technical and organisational measures to ensure and demonstrate compliance, such as policies, procedures, records, audits, reviews, and DPIAs. The controller must also cooperate with the supervisory authority and provide any information requested by it. The other options are not the basis of the accountability and data governance obligation, although they may be related to other obligations under the GDPR. References:
* Article 5(2) of the GDPR3
* ICO guidance on accountability and governance4


質問 # 14
Article 57 of the UK GDPR states that the tasks of the Commissioner include -Select the INCORRECT answer

  • A. Adopting consistency findings in cross-border data protection cases
  • B. Advising UK Parliament on issues related to the protection of personal data
  • C. Handling complaints raised by individuals/data subjects
  • D. Providing general guidance to clarify the law.

正解:A

解説:
Explanation
Article 57 of the UK GDPR states that the tasks of the Commissioner include handling complaints raised by individuals/data subjects, providing general guidance to clarify the law, and advising UK Parliament on issues related to the protection of personal data, among other tasks. However, adopting consistency findings in cross-border data protection cases is not a task of the Commissioner, but of the European Data Protection Board (EDPB), which is an independent body composed of the heads of the supervisory authorities of the EU and EEA member states and the European Data Protection Supervisor. The EDPB is responsible for ensuring the consistent application of the EU GDPR across the EU and EEA, and for issuing opinions and decisions on matters of general application or affecting more than one member state. The UK is no longer part of the EU or the EEA, and therefore the EDPB does not have jurisdiction over the UK GDPR or the Commissioner. The UK has its own mechanism for ensuring consistency and cooperation with other countries, which involves the Commissioner and the Secretary of State. References:
* Article 57 of the UK GDPR1
* Article 63 and 64 of the EU GDPR4
* ICO guidance on the UK GDPR and the EU GDPR5


質問 # 15
If a complainant disagrees with the decision of the UK's supervisory authority, how do they appeal this decision?

  • A. To the Information Commissioner
  • B. To the European Data Protection Supervisor.
  • C. To the First Tier Tribunal (Information Rights)
  • D. To the European Commission

正解:C

解説:
Explanation
If a complainant disagrees with the decision of the UK's supervisory authority, which is the Information Commissioner's Office (ICO), they have the right to appeal to the First Tier Tribunal (Information Rights).
The tribunal is an independent body that can review the ICO's decision and either uphold it, vary it or cancel it. The tribunal can also direct the ICO to take certain actions, such as issuing a decision notice or an enforcement notice. The appeal must be lodged within 28 days of receiving the ICO's decision, using the notice of appeal form and providing the relevant documents and grounds for appeal. The tribunal will then notify the ICO and the complainant of the appeal and the procedure for dealing with it. The tribunal may hold a hearing to examine the evidence and arguments of both parties, or decide the case on the basis of written submissions only. The tribunal will issue a written decision, which will be sent to both parties and published on the tribunal's website. The tribunal's decision can be further appealed tothe Upper Tribunal on a point of law, with the permission of the First Tier Tribunal or the Upper Tribunal. References:
* Information rights and data protection: appeal against the Information Commissioner1
* Notice of appeal form2
* First Tier Tribunal (Information Rights) website3


質問 # 16
Which of the following statements MOST accurately describes the potential impact of Al on the principle of transparency?

  • A. Al can lead to invisible processing, with data subjects not being aware of its presence.
  • B. Transparency requirements do not apply to Al, as it is always compatible with original purposes
  • C. Transparency requirements do not apply to Al, as there is a relevant exemption
  • D. Data subjects should generally expect Al to be present in processing activities

正解:A

解説:
Explanation
The principle of transparency requires that any processing of personal data is fair, lawful and transparent to the data subjects. This means that data subjects should be informed about the existence, nature, purpose and consequences of the processing, as well as their rights and choices regarding their data. Transparency is essential for ensuring accountability, trust and compliance in data processing. However, the use of AI can pose challenges to the principle of transparency, as AI can lead to invisible processing, with data subjects not being aware of its presence, or the logic, significance and implications of the processing. For example, AI can be used to profile, infer, predict or influence the behaviour, preferences, interests, emotions or personality of data subjects, without their knowledge or consent. AI can also be used to make automated decisions that affect data subjects, such as credit scoring, recruitment, health diagnosis or social benefits, without providing meaningful explanations or opportunities for human intervention. Therefore, it is important to ensure that data subjects are informed and empowered when AI is involved in the processing of their data, and that they can exercise their rights, such as the right to access, rectify, object, restrict, erase or port their data, or the right to challenge or contest automated decisions56. References:
* Guidance on AI and data protection5
* Explaining decisions made with AI6


質問 # 17
Which of the following is NOT a processor obligation?

  • A. To provide the controller with corporate information relating to its board members.
  • B. To inform the controller of any intended changes of other processors so they can object
  • C. To consult the controller prior to appointing any processor.
  • D. To follow the instructions of the controller in processing personal data

正解:A

解説:
Explanation
Providing the controller with corporate information relating to its board members is not a processor obligation under the GDPR. The processor obligations under the GDPR are mainly the following:
* To process the personal data only on documented instructions from the controller, unless required by law;
* To ensure that persons authorised to process the personal data are bound by confidentiality;
* To implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk;
* To not engage another processor without the prior authorisation of the controller;
* To assist the controller in fulfilling its obligations regarding data subject rights, data protection impact assessments, prior consultations, and data breach notifications;
* To delete or return the personal data to the controller at the end of the service, unless required by law to store the data;
* To make available to the controller all information necessary to demonstrate compliance and allow for audits and inspections. References:
* Article 28 of the GDPR1
* Guidelines 07/2020 on the concepts of controller and processor in the GDPR2, pp. 37-41


質問 # 18
What does NOT have an exemption prescribed under schedule 3 of the Data Protection Act 2018?

  • A. Credit checking agency data
  • B. Education data, examination scripts and marks
  • C. Health data
  • D. Social Work Data.

正解:A

解説:
Explanation
Schedule 3 of the Data Protection Act 2018 (DPA 2018) provides exemptions from some of the UK GDPR provisions for certain types of personal data processing, such as health data, social work data, education data, and child abuse data. These exemptions are intended to balance the rights and freedoms of data subjects with the public interest or the legitimate interests of data controllers in specific contexts. For example, the exemptions may allow data controllers to restrict the data subjects' access to their personal data, or to process their personal data without their consent, if complying with the UK GDPR would be likely to prejudice the purposes of the processing, such as the provision of health care, social work, education, or child protection.
However, Schedule 3 of the DPA 2018 does not provide any exemption for credit checking agency data, which is personal data processed by credit reference agencies for the purposes of assessing the creditworthiness of individuals or organisations, or preventing fraud or money laundering. Credit checking agency data is subject to the UK GDPR provisions as normal, unless another exemption applies. For example, credit reference agencies may rely on the crime and taxation exemption in Schedule 2, Part 1, Paragraph 2 of the DPA 2018 if disclosing personal data to a data subject would be likely to prejudice the prevention or detection of crime, or the apprehension or prosecution of offenders. References:
* Data Protection Act 2018, Schedule 31
* ICO Guide to Data Protection, Exemptions2
* ICO Guide to Data Protection, Credit3


質問 # 19
Article 9(2)(c) of UK GDPR condition of processing special category data in the vital interests of the data subject is only applicable in which of the following circumstances:

  • A. When the data subject is physically unable to be present
  • B. When another lawful basis applies.
  • C. When the data subject refuses to consent
  • D. When a data subject is incapacitated

正解:D

解説:
Explanation
Article 9(2) of UK GDPR allows the processing of special category data when it is necessary to protect the vital interests of the data subject or of another natural person where the data subject is physically or legally incapable of giving consent. This means that the data subject is unable to exercise their right to consent or object to the processing, either because they are unconscious, in a coma, suffering from a severe mental disorder, or otherwise unable to communicate their wishes. This condition is intended to cover emergency situations, such as life-threatening medical interventions, where the data subject's consent cannot be obtained in time. It does not apply when another lawful basis applies, when the data subject is physically absent but still capable of giving consent, or when the data subject refuses to consent. References:
* Article 9(2) of UK GDPR1
* ICO guidance on special category data2


質問 # 20
Under the Privacy and Electronic Communications Regulations, organisations must NOT make marketing telephone calls to which of the following?

  • A. Any person outside of the United Kingdom.
  • B. Any person under the age of 18, unless their parent or guardian has provided permission
  • C. Any person who has not consented to receiving marketing calls
  • D. Any person who is registered with the Telephone Preference Service, unless they have given specific consent to receive your calls

正解:D

解説:
Explanation
The Privacy and Electronic Communications Regulations (PECR) are a set of rules that regulate the use of electronic communications for marketing purposes, such as phone calls, texts, emails and faxes. One of the rules is that organisations must not make unsolicited marketing calls to individuals who have registered their numbers with the Telephone Preference Service (TPS), unless they have given their prior consent to receive such calls from that organisation. The TPS is a free service that allows individuals to opt out of receiving any marketing calls. It is a legal requirement for organisations to check the TPS before making any marketing calls and to respect the preferences of the individuals registered on it. If an organisation fails to comply with this rule, it may face enforcement action from the Information Commissioner's Office (ICO), which is the UK's data protection authority and the regulator of PECR. References:
* Telephone Preference Service
* Marketing calls
* Enforcement action


質問 # 21
What does NOT have an exemption prescribed under schedule 3 of the Data Protection Act 2018?

  • A. Credit checking agency data
  • B. Education data, examination scripts and marks
  • C. Health data
  • D. Social Work Data.

正解:A


質問 # 22
Describe the act of processing under the authority of a controller or processor as stipulated in UK GDPR Article 29.

  • A. The processor shall implement appropriate technical and organisational measures for ensuring that, by default, only personal data which are necessary for each specific purpose of the processing are processed.
  • B. The processor shall consult the supervisory authority prior to processing where a data protection impact assessment indicates that the processing would result in a high risk in the absence of measures taken by the processor to mitigate the risk.
  • C. Each processor and, where applicable, the processors representative shall maintain a record of all categories of processing activities earned out on behalf of a controller.
  • D. A processor shall not process those data except on instructions from the controller, unless required to do so by domestic law

正解:D

解説:
Explanation
Article 29 of UK GDPR states that the processor and any person acting under the authority of the controller or of the processor, who has access to personal data, shall not process those data except on instructions from the controller, unless required to do so by domestic law. This means that the processor must follow the controller's directions on how to handle the personal data, and cannot use it for its own purposes or deviate from the agreed terms. The only exception is when the processor is obliged by law to process the data in a different way, for example, to comply with a court order or a legal obligation. The other options are not related to Article 29, but to other articles of UK GDPR, such as Article 25 (data protection by design and by default), Article 30 (records of processing activities), and Article 36 (prior consultation). References:
* Article 29 of UK GDPR1
* ICO guidance on controllers and processors2


質問 # 23
Which one task are supervisory authorities NOT required to carry out under Article 57(1 )(f) of the UK GDPR? Select the CORRECT answer.

  • A. Co-ordinate where necessary with other supervisory authorities
  • B. Investigate complaints and inform the complainant of the progress of their investigation
  • C. Mediate between the complainant and the entity against which the complaint has been lodged, to resolve the complaint
  • D. Handle complaints lodged by a data subject

正解:C

解説:
Explanation
Article 57(1)(f) of the UK GDPR requires the supervisory authority (the ICO in the UK) to handle complaints lodged by a data subject, investigate the subject matter of the complaint, and inform the complainant of the progress and the outcome of the investigation. It also requires the supervisory authority to cooperate with other supervisory authorities if the complaint involves cross-border processing. However, it does not require the supervisory authority to mediate between the complainant and the controller or processor against which the complaint has been lodged, to resolve the complaint. This is not a task of the supervisory authority under the UK GDPR, although it may be possible in some cases as a way of achieving an amicable solution. References
:
* Article 57(1)(f) of the UK GDPR1
* ICO and complaints2


質問 # 24
Where a processor engages another processor ("sub-processor") to carry out processing activities on behalf of a controller, which of the following statements is CORRECT?

  • A. The processor may use the sub-processor without the written authorisation of the controller if the processing is deemed to be low risk.
  • B. The processor may use the sub-processor without the written authorisation of the controller if the sub-processor signs a contract which reflects the same obligations as the contract with the controller
  • C. The processor must receive prior written authorisation to use the sub-processor
  • D. The processor may use the sub-processor without the written authorisation of the controller if it adheres to an approved code of conduct

正解:C

解説:
Explanation
Article 28(2) of UK GDPR states that where a processor engages another processor ("sub-processor") for carrying out specific processing activities on behalf of the controller, the same data protection obligations as set out in the contract or other legal act between the controller and the processor shall be imposed on that other processor by way of a contract or other legal act under domestic law, in particular providing sufficient guarantees to implement appropriate technical and organisational measures in such a manner that the processing will meet the requirements of UK GDPR. The processor shall not engage another processor without prior specific or general written authorisation of the controller. In the case of general written authorisation, theprocessor shall inform the controller of any intended changes concerning the addition or replacement of other processors, thereby giving the controller the opportunity to object to such changes. The other options are incorrect, as they do not reflect the requirements of UK GDPR for using a sub-processor. The processor cannot use a sub-processor without the written authorisation of the controller, regardless of whether it adheres to an approved code of conduct, signs a contract with the same obligations as the controller, or deems the processing to be low risk. References:
* Article 28(2) of UK GDPR1
* ICO guidance on contracts and liabilities between controllers and processors3


質問 # 25
When were data protection rights first introduced into UK law'?

  • A. 2018 (Data Protection Act 2018)
  • B. 2000 (Data Protection Act 1998)
  • C. 1992 (Data Protection Act 1992).
  • D. 1984 (Data Protection Act 1984).

正解:D

解説:
Explanation
Data protection rights were first introduced into UK law by the Data Protection Act 1984, which was enacted to implement the Council of Europe Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data of 1981. The Data Protection Act 1984 established a set of principles for the processing of personal data by data users, such as obtaining consent, ensuring accuracy, and limiting retention.
It also created a system of registration for data users and a Data Protection Registrar (later renamed as the Information Commissioner) to oversee and enforce the law. The Data Protection Act 1984 was replaced by the Data Protection Act 1998, which transposed the EU Data Protection Directive 1995 into UK law and extended the scope of data protection to cover manual as well as automated processing of personal data. The Data Protection Act 1998 was further amended by the Data Protection Act 2018, which incorporated the EU General Data Protection Regulation (GDPR) and the Law Enforcement Directive into UK law and made provisions for specific processing situations, such as national security, immigration, and journalism.
References:
* Data Protection Act 19844
* Council of Europe Convention 1085
* Data Protection Act 19986
* Data Protection Act 20187


質問 # 26
What is the meaning of storage limitation in relation to UK GDPR Article 5 (1 )(e)?

  • A. Storing data in a secure format only permitting access to those with a business need
  • B. Limiting the number of records stored in any single repository to minimise risk surface.
  • C. Only storing data in locations within the EU. except where there is an adequacy decision.
  • D. Keeping identifiable personal data for no longer than is necessary for the intended processing

正解:D

解説:
Explanation
Storage limitation is one of the principles of data protection under the UK GDPR. It means that personal data should not be kept in a form that allows identification of data subjects for longer than is necessary for the purposes for which the data are processed. The UK GDPR does not specify any fixed time limits for different types of data, but rather requires data controllers to determine and justify the appropriate retention periods for their processing activities, taking into account factors such as the nature, scope, context and purposes of the processing, the risks to the rights and freedoms of data subjects, and the legal obligations and expectations of the data controller. Data controllers should also have a policy setting out standard retention periods where possible, and review the data they hold regularly to ensure that it is erased or anonymised when it is no longer needed. Data subjects have the right to request the erasure of their personal data if the data controller no longer has a lawful basis or a legitimate interest for keeping it. The UK GDPR allows for some exceptions to the storage limitation principle, such as when the personal data is processed solely forarchiving purposes in the public interest, scientific or historical research purposes, or statistical purposes, subject to appropriate safeguards for the rights and freedoms of data subjects. References:
* UK GDPR, Article 5 (1) (e) and (2)4
* UK GDPR, Article 175
* UK GDPR, Article 896
* ICO Guide to Data Protection, Storage Limitation7


質問 # 27
How are data sharing practices governed by data protection law?

  • A. Data sharing practices are covered by the Freedom of Information Act
  • B. Data sharing practices are covered in the DPA 2018, supported by a statutory Code of Practice that provides specific guidance
  • C. Data sharing practices are not specifically regulated, however the ICO provide best practice guidance
  • D. Data sharing practices are subject to the PECR until the new statutory Code of Practice is published

正解:B

解説:
Explanation
Data sharing is the disclosure of personal data from one or more organisations to a third party organisation or organisations, or the sharing of personal data within an organisation. Data sharing practices are governed by data protection law, which includes the UK GDPR and the Data Protection Act 2018 (DPA 2018). The DPA
2018 contains specific provisions on data sharing, such as the power of the Information Commissioner's Office (ICO) to issue a statutory Code of Practice on data sharing. The ICO has published a Data Sharing Code of Practice1 that provides practical guidance on how to share data in a fair, safe and transparent way, in compliance with the data protection principles and the rights of data subjects. The code is not legally binding, but it reflects the ICO's interpretation of the law and it may be used as evidence in legal proceedings or investigations. The code also contains useful tools, case studies andexamples that can help organisations to share data effectively and responsibly. References:
* Data Sharing Code of Practice1


質問 # 28
......

あなたの合格を助けるBCS認証と最新のGoShiken PDP9試験問題集解答:https://drive.google.com/open?id=1RoynFAb0MjVwJjHktB214LAdC93xw8lo

最新PDP9問題集試験解答はここにある:https://www.goshiken.com/BCS/PDP9-mondaishu.html