1.  A company which determines the purposes and means of processing of personal data. What type of organisation does this describe?

  • (a)   A participant
  • (b)   A data subject
  • (c)   A controller
  • (d)   Personal data

2.  For consent to be sufficient which of the following is required?

  • (a)   It must be specific
  • (b)   It must be in writing
  • (c)   It must have been collected in the last month
  • (d)   All of the above

3.  You have been given a client supplied database of customers to undertake recruitment for research on the client’s behalf. Do you…

  • (a)   Undertake the recruitment and return the list to the client
  • (b)   Undertake the recruitment and keep the list to build a recruitment database
  • (c)   Undertake the recruitment and keep the list just in case you might need it in future
  • (d)   Any of the above – they are all in line with GDPR

4.  In the UK research sector what is the definition of a child?

  • (a)   Under 16 years old
  • (b)   Under 18 years old
  • (c)   Under 14 years old
  • (d)   None of the above

5.  Which of the following are data subject, i.e. individual, rights within the GDPR?

  • (a)   Right of access
  • (b)   Right to erasure
  • (c)   Right to data portability
  • (d)   All of the above

6.  When is it a requirement to report a data breach to the data subject, i.e. individuals, affected?

  • (a)   For all breaches
  • (b)   The breach has a high risk of affecting individual rights
  • (c)   There is no requirement to report breaches to data subjects
  • (d)   When digital data has been breached
You haven't answered the questions