Which statement best describes GDPR data subject rights and breach notification requirements?

Prepare for the MITIL Exam with interactive flashcards and multiple-choice questions. Each question comes with detailed explanations and hints, building your confidence for exam success!

Multiple Choice

Which statement best describes GDPR data subject rights and breach notification requirements?

Explanation:
The question tests understanding of GDPR rights for individuals and when breaches must be reported. Under GDPR, data subjects have several rights beyond erasure, including access to their data and data portability (the ability to obtain a copy of their data in a structured, commonly used format and to have it transmitted to another controller). On breach notification, the rule is that a data controller must report a personal data breach to the supervisory authority within 72 hours of becoming aware of it if there’s a risk to rights and freedoms. If there is a high risk to individuals, those affected must be informed without undue delay. The statement that combines these rights (access, erasure, data portability) with the 72-hour notice to authorities and to individuals when there’s risk accurately reflects GDPR obligations. The other options misstate the scope of rights or the notification rules—for example, suggesting rights are limited to erasure and that there’s no notification timeframe, or implying data can be stored forever with no breach notices.

The question tests understanding of GDPR rights for individuals and when breaches must be reported. Under GDPR, data subjects have several rights beyond erasure, including access to their data and data portability (the ability to obtain a copy of their data in a structured, commonly used format and to have it transmitted to another controller). On breach notification, the rule is that a data controller must report a personal data breach to the supervisory authority within 72 hours of becoming aware of it if there’s a risk to rights and freedoms. If there is a high risk to individuals, those affected must be informed without undue delay. The statement that combines these rights (access, erasure, data portability) with the 72-hour notice to authorities and to individuals when there’s risk accurately reflects GDPR obligations. The other options misstate the scope of rights or the notification rules—for example, suggesting rights are limited to erasure and that there’s no notification timeframe, or implying data can be stored forever with no breach notices.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy