OneTrust Certified Privacy Professional Practice Exam

Image Description

Question: 1 / 400

Which of the following practices is NOT compliant with GDPR?

Training employees on data protection regulations

Collecting data without user consent

The practice of collecting data without user consent is not compliant with the General Data Protection Regulation (GDPR). Under GDPR, one of the core principles is obtaining explicit consent from individuals before collecting and processing their personal data. This requirement applies to most types of personal data and is critical in ensuring that individuals have control over their information and can make informed decisions regarding its use. Without consent, data subjects have not agreed to the data collection, which violates their privacy rights as established by GDPR. Consent must be freely given, specific, informed, and unambiguous, and simply bypassing this requirement undermines the very foundation of the regulation.

The other practices mentioned—training employees on data protection regulations, implementing robust security measures for data, and providing individuals with access to their personal data—are aligned with GDPR compliance. Training ensures that employees understand their responsibilities regarding data protection, security measures are essential for protecting personal data from breaches, and providing access is a fundamental right under GDPR that allows individuals to verify the data being held about them and how it is being used.

Get further explanation with Examzify DeepDiveBeta

Implementing robust security measures for data

Providing individuals with access to their personal data

Next Question

Report this question

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy