GDPR
The EU regulation governing personal data end to end — a lawful basis for every processing activity, enforceable rights for data subjects, breach reporting deadlines, and rules on moving data abroad. Interviewers ask because GDPR turns into concrete engineering work: deletion paths, consent records, retention limits and audit trails.
part ofCompliance & governance standardsoverview, primer and where to startread it →on this pageshowhide
explore
- Scope and Key Definitions6 questions
- Lawful Bases for Processing6 questions
- Data Subject Rights6 questions
- Consent Requirements6 questions
- Breach Notification and DPO6 questions
- Cross-Border Transfers and Penalties6 questions
questions
page 2 of 2Under GDPR Art. 22, when may a lender's system refuse a credit application with no human involved, and what must it offer the applicant?
basics
~20 sUnder GDPR Art. 22, a solely automated credit refusal is allowed only if necessary for the contract, authorised by law, or based on explicit consent; for contract and consent the lender must offer human intervention and the chance to state a view and contest.
Under GDPR Art. 6(4), can an online shop reuse order data collected for fulfilment to build sales analytics without a new basis?
basics
~20 sUnder GDPR Art. 6(4), reuse is allowed if the new purpose is compatible with the original, judged on the link, context, data nature, consequences and safeguards. Aggregate sales analytics usually passes; using the history to target individuals needs its own assessment.
Under the GDPR, which lawful basis can an employer use to monitor staff laptops, and why does employee consent rarely work?
basics
~20 sUnder the GDPR, employee consent is rarely valid because refusing an employer is risky (Recital 43; EDPB Guidelines 05/2020). Laptop monitoring usually rests on legitimate interests such as security, after documented necessity and balancing, or on a legal obligation.
Under the GDPR, your payroll processor starts using clients' pooled employee salary data to sell a pay benchmark; what does that make it, and what follows?
basics
~20 sUnder GDPR Art. 28(10), a processor that determines purposes and means in breach of the Regulation is treated as a controller for that processing, while remaining liable for the infringement. The client must act on its own Art. 28 duties.
Under the GDPR, an EU subsidiary sends employee HR data to its US parent; which transfer mechanisms fit, and when are binding corporate rules worth it?
basics
~20 sUnder the GDPR an intra-group flow is still a transfer. It can rely on an HR-covering DPF listing, on SCCs chosen by role, or on Art. 47 BCRs, which pay off for groups with many entities and flows.
Under the GDPR after Schrems II (case C-311/18), why may signing the 2021 standard contractual clauses not be enough to make a transfer lawful?
basics
~20 sUnder the GDPR, SCCs bind only exporter and importer, not the destination's authorities. After Schrems II, Clause 14 of the 2021 SCCs requires assessing local law, adding supplementary measures where needed, and suspending the transfer if protection cannot be ensured.
showing 31–36 of 36