Client GDPR and Protecting Information Quiz Play Pause Unmute Mute Do you know the GDPR laws? Is your businesses following GDPR and protecting information correctly? Answer the questions below to find out… Cyber Security - GDPR and Protecting Information Your Company Name*Name* First Last Your email address* What is the main risk if you don't handle confidential information properly?*The information could be stolen.The information could be incorrect.The information could be difficult to find.The information could be destroyed.Which of these is a risk that might be caused by exposing your personal information on the internet?*Application errorsNetwork failureI might not be able to log inMy reputation could be affectedWhich statement about downloading security patches is correct?*It is not essential, because it is fine to wait for the next release.It is a waste of time and money, because previous versions work fine.It is not effective, because your data may be stolen anyway.It is essential, because it protects your personal informationThe GDPR only applies to organizations that...*charge fees for their products or services.offer products or services into the EU.process hardcopy personal data.offer social networking platforms.Which is an example of sensitive personal information?*My work addressMy date of birthMy nameMy job titleYou have encrypted some customer data that you are going to send to another office. How should you send the password?*I should text the password to the email recipient.I should include the password in the email with the confidential data.I should send the password in a separate email to the confidential data.The email with the data should tell the other office to phone me and ask for the passwordYou want to transfer some data at work using a USB stick. What should you do?*Only use a USB stick that has no other data on itOnly use a USB stick for transferring non-confidential informationOnly use a USB stick that I have purchased myselfOnly use a USB stick that has been provided by the IT departmentWhat type of information would have a very low impact if it was leaked to criminals?*The names and addresses of customersThe content of marketing brochuresThe company's internal phone bookThe business case for a new productWhat is the GDPR?*A data deletion softwareA guidance for driverless carsA data protection lawThe rules governing a financial transactionIn what situation must data controllers NOT retain data?*When the data is more than 10 years oldWhen the data processor has changed and has been replaced by a new processorWhen money can't be made from the data anymoreWhen there is no legal obligation, or the data is no longer requiredUnder the GDPR, which is a right you have as a 'data subject'?*The right to have access to my informationThe right to be paid for my informationThe right to sell my informationThe right to move my information to the cloudUnder the GDPR, in which situation can a data controller process personal data?*When the data needs to be transferred to a third partyWhen the data processor wants to send out marketing emailsWhen the data controller is interested in processing personal dataWhen there is a legal obligation to process the dataHow should you use a USB stick securely?*Only use an approved one that has been provided by your employerOnly use one with a capacity that is just large enough to store the information you want to put on itOnly use one that has been purchased from an approved supplierOnly use one that has been used several times before, as it will be safeYou must exercise your right to [?], if you want to move data that you provided to a new service provider.*consentaccessdeletionportabilityWhich is the BEST way of securing sensitive information stored on removable devices?*Keep the removable device wrapped in protective materialOnly use the device once so that it won't be overused and damagedPassword protect and encrypt the data on the removable deviceCheck the data on the device regularly to make sure it is completeIf your personal information is stolen, you...*cannot prove your identity.cannot change your password.may forget your password.may be the victim of fraud.What is an impact of losing a removable device containing sensitive company information?*The company may be fined by a regulator for the loss of information.The security patches on my computer will not be kept up to date.The company will have to update the anti-virus software on all computers.Criminals will be able to install malware programmes on my computer.An organization processing your data must ensure that your data...*is always saved in the cloud and encrypted.is anonymized.is always processed lawfully.is shared with other companies.How must data always be processed?*Lawfully, fairly, and in a transparent mannerWith consent from the data sellerElectronically and in a digital formatIn a data centre to ensure availability at all timesYou are walking into a shop when you see a memory stick on the floor. What should you do?*Ignore it, because it would be stealing to pick it upTake it home and use it for non-sensitive informationFormat and run a virus scan on it before using itTake it home and use it for personal informationYou just bought a new mobile phone and put your data on it. What should you do with your old phone to protect your personal information?*I should make sure that my personal information is permanently removed using a memory wipe utility or factory reset functionI should sell it on a trustworthy auction site because it will only be purchased by a trustworthy person.I should keep it stored in a safe place until the personal information on it is out of date.I should check that I did not forget to transfer any of my personal information from it to the new phoneUnder the GDPR, what should be considered when processing personal data?*How much data can be stored on the system, and whether cloud services will be requiredWhether the data subject cares about the processing of their personal dataHow long it will take to collect and process the dataThe impact on the rights and freedoms of the data subjectHow should customer information be handled?*With enough care not to destroy itIn accordance with company rulesBy encrypting it at all timesLike any other piece of informationWhen should you use software to lock your computer screen?*When I am typing confidential informationWhen it is shut down and safely storedWhen I'm not actually typing anythingWhen it is not in useAgreement - Your data will be retained for the anonomised purpose of statistical analysis* I agree EmailThis field is for validation purposes and should be left unchanged.