← Galeria de templates
GDPR 2026 — Fundamentals & Updates
Test your grasp of GDPR obligations in force in 2026, including post-Schrems II transfer rules.
EN
Compliance
7 perguntas
· 0 ↪
Pré-visualização
-
Under Article 33 GDPR, within what timeframe must a personal data breach be reported to the supervisory authority?
[single_choice]
- · 24 hours
- · 48 hours
- ✓ 72 hours
- · 5 business days
-
Which EU-US data transfer framework replaced the Privacy Shield after the Schrems II ruling?
[single_choice]
- · Safe Harbor 2.0
- ✓ EU-US Data Privacy Framework (DPF), adopted July 2023
- · Standard Contractual Clauses v3 (SCCv3)
- · Binding Corporate Rules (BCR) for transfers
-
An employee submits a Subject Access Request (SAR). What is the default response deadline?
[single_choice]
- · 14 calendar days
- ✓ 30 calendar days (extendable by 2 months for complexity)
- · 60 calendar days
- · 90 calendar days
-
Which of the following are valid lawful bases for processing personal data under GDPR Article 6? (select all that apply)
[multiple_choice]
- ✓ Consent of the data subject
- ✓ Performance of a contract
- · Commercial interest of a third-party advertiser
- ✓ Compliance with a legal obligation
- ✓ Legitimate interests of the controller (if not overridden)
-
Every organisation that processes personal data is legally required to appoint a Data Protection Officer (DPO).
[true_false]
- · True
- ✓ False
-
Consent obtained before GDPR came into force (May 2018) remains valid indefinitely, provided it was freely given, specific, and informed.
[true_false]
- · True
- ✓ False
- Your company uses a US-based CRM that transfers EU customer data to the US. Outline the steps you would take to ensure compliance with GDPR Chapter V on international transfers. [open_text]