skip to content

GDPR

The EU regulation governing personal data end to end — a lawful basis for every processing activity, enforceable rights for data subjects, breach reporting deadlines, and rules on moving data abroad. Interviewers ask because GDPR turns into concrete engineering work: deletion paths, consent records, retention limits and audit trails.

part ofCompliance & governance standardsoverview, primer and where to startread it →
on this pageshow

questions

page 2 of 2

Under GDPR Art. 22, when may a lender's system refuse a credit application with no human involved, and what must it offer the applicant?

level: seniorimportance: should knowfreq 50%

basics

~20 s

Under GDPR Art. 22, a solely automated credit refusal is allowed only if necessary for the contract, authorised by law, or based on explicit consent; for contract and consent the lender must offer human intervention and the chance to state a view and contest.

open as a page

Under GDPR Art. 6(4), can an online shop reuse order data collected for fulfilment to build sales analytics without a new basis?

level: seniorimportance: should knowfreq 38%

basics

~20 s

Under GDPR Art. 6(4), reuse is allowed if the new purpose is compatible with the original, judged on the link, context, data nature, consequences and safeguards. Aggregate sales analytics usually passes; using the history to target individuals needs its own assessment.

open as a page

Under the GDPR, which lawful basis can an employer use to monitor staff laptops, and why does employee consent rarely work?

level: seniorimportance: should knowfreq 42%

basics

~20 s

Under the GDPR, employee consent is rarely valid because refusing an employer is risky (Recital 43; EDPB Guidelines 05/2020). Laptop monitoring usually rests on legitimate interests such as security, after documented necessity and balancing, or on a legal obligation.

open as a page

Under the GDPR, your payroll processor starts using clients' pooled employee salary data to sell a pay benchmark; what does that make it, and what follows?

level: seniorimportance: should knowfreq 36%

basics

~20 s

Under GDPR Art. 28(10), a processor that determines purposes and means in breach of the Regulation is treated as a controller for that processing, while remaining liable for the infringement. The client must act on its own Art. 28 duties.

open as a page

Under the GDPR, an EU subsidiary sends employee HR data to its US parent; which transfer mechanisms fit, and when are binding corporate rules worth it?

level: seniorimportance: should knowfreq 40%

basics

~20 s

Under the GDPR an intra-group flow is still a transfer. It can rely on an HR-covering DPF listing, on SCCs chosen by role, or on Art. 47 BCRs, which pay off for groups with many entities and flows.

open as a page

Under the GDPR after Schrems II (case C-311/18), why may signing the 2021 standard contractual clauses not be enough to make a transfer lawful?

level: seniorimportance: should knowfreq 50%

basics

~20 s

Under the GDPR, SCCs bind only exporter and importer, not the destination's authorities. After Schrems II, Clause 14 of the 2021 SCCs requires assessing local law, adding supplementary measures where needed, and suspending the transfer if protection cannot be ensured.

open as a page

showing 31–36 of 36