PC-DP BCS Practitioner Certificate in Data Protection Practice Questions
Prepare for PC-DP with more than an answer.
- Time limit
- 90 minutes
- Questions on the exam
- 40
- Passing score
- 26/40 (65%)
- Level
- Practitioner
- Valid for
- Lifetime (no expiry)
Domains covered on the exam 14
- Context of Data Protection Legislation7.5%
- Principles of Data Protection and Applicable Terminology5%
- Lawful Bases for Processing Personal Data5%
- Accountability Principle15%
- Obligations of Controllers, Joint Controllers and Data Processors10%
- International Data Transfers under EU and UK GDPR2.5%
- Data Subject Rights5%
- The Role of Independent Supervisory Authorities and the ICO7.5%
- Breaches, Enforcement and Liability12.5%
- Processing of Personal Data in Relation to Children2.5%
- Specific Provisions Relevant to Public Authorities7.5%
- Privacy and Electronic Communications (EC Directive) Regulations (PECR) 20035%
- Application of Data Protection Legislation in Key Areas of Industry7.5%
- AI and the Processing of Personal Data7.5%
- 1
A recruitment agency purchases a large database of candidate CVs from an external, third-party job board. Because the recruitment agency obtained this personal data indirectly (not directly from the candidates themselves), they must provide a privacy notice to these candidates.
Under Article 14 of the UK GDPR, what is the maximum timeframe the recruitment agency has to provide this privacy information to the candidates?
Show answer details
Correct answer: D
According to Article 14(3)(a) of the UK GDPR, when personal data has not been obtained directly from the data subject, the controller must provide the privacy information within a reasonable period after obtaining the personal data, but at the latest within one month. (Note: If the data is used to communicate with the subject, it must be provided at the latest at the time of the first communication).
- 2
True or False: Under Article 25 of the UK GDPR, the concept of 'Data Protection by Default' means that an organization can simply change its lawful basis from 'Consent' to 'Legitimate Interests' in its privacy policy to automatically protect the user without requiring them to click a consent banner.
Show answer details
Correct answer: B
False. Switching a lawful basis does not illustrate Data Protection by Default. Article 25 requires controllers to implement appropriate technical and organizational measures ensuring that, by default, only personal data which are necessary for each specific purpose of the processing are processed. This relates to the amount of data collected, the extent of processing, the period of storage, and accessibility (e.g., pre-ticked boxes opting users into data sharing violate privacy by default).
- 3
According to Article 39 of the UK GDPR, a designated Data Protection Officer (DPO) has several mandatory, statutory tasks they must perform. Which TWO of the following are explicitly listed as formal tasks of the DPO? (Select TWO)
Show answer details
Correct answer: A, E
Article 39(1) of the UK GDPR explicitly lists the tasks of the DPO. These include (a) informing and advising the controller/processor and employees of their obligations, and (c) providing advice where requested as regards the data protection impact assessment (DPIA) and monitoring its performance.
Article 39(1) of the UK GDPR explicitly lists the tasks of the DPO. These include (a) informing and advising the controller/processor and employees of their obligations, and (c) providing advice where requested as regards the data protection impact assessment (DPIA) and monitoring its performance.
- 4
A local municipal council, the Borough of Oakhaven, installs covert surveillance cameras in a public park to identify individuals engaging in persistent fly-tipping (illegal waste dumping). A local civil liberties group challenges this action, citing a breach of the individuals' right to respect for private and family life. Under the context of the Human Rights Act 1998 and the European Convention on Human Rights (ECHR), which of the following statements is technically accurate regarding this scenario?
Show answer details
Correct answer: C
Article 8 of the European Convention on Human Rights (ECHR) provides the right to respect for private and family life, home, and correspondence. However, it is a 'qualified' right, not an absolute one. This means a public authority can sometimes interfere with this right if it is in accordance with the law, pursues a legitimate aim (such as the prevention of crime), and is necessary and proportionate. Covert surveillance must be heavily justified but is not inherently forbidden in all circumstances.
- 5
True or False: A cloud software provider headquartered exclusively in Tokyo, Japan, with no offices or representatives in the United Kingdom, offers a specialized accounting application. The application allows users to select 'Great British Pounds (GBP)' as a currency, provides a dedicated UK customer service phone line, and actively runs targeted social media campaigns aimed at London-based financial firms. Under Article 3 of the UK GDPR, the Tokyo-based provider is completely exempt from UK data protection legislation because they have no physical establishment in the UK.
Show answer details
Correct answer: B
Article 3 of the UK GDPR contains extra-territorial provisions. Even without a physical presence in the UK, a controller or processor based outside the UK is subject to the UK GDPR if they process personal data of individuals in the UK in relation to the offering of goods or services to them, or the monitoring of their behavior. The use of GBP, targeted campaigns, and dedicated UK lines clearly indicate an intention to offer services to individuals in the UK.
- 6
Following the UK's departure from the European Union, the legislative framework for data protection in the UK underwent significant structural changes. Which of the following best describes the core mechanism that established the 'UK GDPR'?
Show answer details
Correct answer: A
To ensure legal continuity post-Brexit, the UK retained the EU GDPR in domestic law via the European Union (Withdrawal) Act 2018. It was then modified by the Data Protection, Privacy and Electronic Communications (Amendments etc) (EU Exit) Regulations 2019 to make it function effectively in a UK-only context, resulting in what is now known as the UK GDPR.
