Assessment: GDPR

GDPR

GDPR

The legislative and operational concerns of General Data Protection Regulation and how it relates to the maritime industry.

0%
2

Assessment: GDPR

  • 15
  • Questions
  • No time limit
  • 2
  • Attempts left
  • 70%
  • Passing threshold

Question 1 of 15

Maritime Safety Committee (MSC) and The Facilitation Committee (FAL) have issued “Guidelines on maritime cyber risk management” as an answer to what?

Question 2 of 15

GDPR is brought by the European Union and is applicable to the EU area only. Is this statement true or false?

Question 3 of 15

Which of the following statements is true when it comes to a vessel's commercial data?

Question 4 of 15

Data subjects can withdraw previously given consent whenever they want and the organisation needs to honour their decision. Is this statement true or false?

Question 5 of 15

In case of a cyber-attack onboard, what systems are vulnerable?

Select multiple answers:

Question 6 of 15

As an organisation, I must always appoint a Data Processing Officer. Is this statement true or false?

Question 7 of 15

The advantage of the 'NIST framework' lies in its local application and exactingness, which is why it can be employed in many industries, including the maritime one. Is this statement true or false?

Question 8 of 15

The NIST framework covers five areas that are essential for a successful cybersecurity framework. Which of the following is not part of these five areas?

Question 9 of 15

As a seafarer on board, it doesn´t matter if I use company computers for personal usage. Is this statement true or false?

Question 10 of 15

Fill in the sentence: The GDPR sites supervisory authorities the power to issue fines of up to €20 million or __% of the breached organisations annual global turnover.

Question 11 of 15

What is the data subject?

Question 12 of 15

Data Protection Directive (DPD) was replaced with General Data Protection Regulation (GDPR) in what year?

Question 13 of 15

What is personal data?

Question 14 of 15

Which of the following is not part of the 7 key principles?

Question 15 of 15

When there has been a violation of personal privacy, within what time period are companies obligated to report system violations?

You Passed This Quiz. Let’s Move On!

Good work! You just completed the quiz Assessment: GDPR . Let’s move on to the next.

Maritime Safety Committee (MSC) and The Facilitation Committee (FAL) have issued “Guidelines on maritime cyber risk management” as an answer to what?

DPD
Your answer
Cyber attacks
Your answer
GDPR
Your answer

GDPR is brought by the European Union and is applicable to the EU area only. Is this statement true or false?

True
Your answer
False.
Your answer

Which of the following statements is true when it comes to a vessel's commercial data?

A vessel's commercial data is never subject to GDPR.
Your answer
A vessel's commercial data is always subject to GDPR.
Your answer
A vessel's commercial data is only subject to GDPR if it includes personal data.
Your answer

Data subjects can withdraw previously given consent whenever they want and the organisation needs to honour their decision. Is this statement true or false?

True
Your answer
False
Your answer

In case of a cyber-attack onboard, what systems are vulnerable?

Crew TV
Your answer
Engine room
Your answer
Navigation bridge
Your answer
Personal CO2 monitors
Your answer

As an organisation, I must always appoint a Data Processing Officer. Is this statement true or false?

True
Your answer
False
Your answer

The advantage of the 'NIST framework' lies in its local application and exactingness, which is why it can be employed in many industries, including the maritime one. Is this statement true or false?

True
Your answer
False
Your answer

The NIST framework covers five areas that are essential for a successful cybersecurity framework. Which of the following is not part of these five areas?

Response
Your answer
Identification
Your answer
Protection
Your answer
Installation
Your answer

As a seafarer on board, it doesn´t matter if I use company computers for personal usage. Is this statement true or false?

True
Your answer
False
Your answer

Fill in the sentence: The GDPR sites supervisory authorities the power to issue fines of up to €20 million or __% of the breached organisations annual global turnover.

2
Your answer
4
Your answer
6
Your answer

What is the data subject?

The person who denied why and how personal data would be processed.
Your answer
A third party that process personal data on behalf of a data controller.
Your answer
The person whose data is processed
Your answer

Data Protection Directive (DPD) was replaced with General Data Protection Regulation (GDPR) in what year?

2020
Your answer
2014
Your answer
2018
Your answer
2016
Your answer

What is personal data?

An e-mail address.
Your answer
Anonymised data.
Your answer
Any information related to an identified or identifiable natural person.
Your answer
A registration number of a company.
Your answer

Which of the following is not part of the 7 key principles?

Integrity and confidentiality
Your answer
Purpose limitation
Your answer
Empathy
Your answer
Accuracy
Your answer

When there has been a violation of personal privacy, within what time period are companies obligated to report system violations?

1 month
Your answer
72 hours
Your answer
24 hours
Your answer
1 week
Your answer
Score: Attempts:

Too Bad! But That Wasn't Enough

Unfortunately you didn’t have enough correct answers to pass the quiz. Try again!

Maritime Safety Committee (MSC) and The Facilitation Committee (FAL) have issued “Guidelines on maritime cyber risk management” as an answer to what?

DPD
Your answer
Cyber attacks
Your answer
GDPR
Your answer

GDPR is brought by the European Union and is applicable to the EU area only. Is this statement true or false?

True
Your answer
False.
Your answer

Which of the following statements is true when it comes to a vessel's commercial data?

A vessel's commercial data is never subject to GDPR.
Your answer
A vessel's commercial data is always subject to GDPR.
Your answer
A vessel's commercial data is only subject to GDPR if it includes personal data.
Your answer

Data subjects can withdraw previously given consent whenever they want and the organisation needs to honour their decision. Is this statement true or false?

True
Your answer
False
Your answer

In case of a cyber-attack onboard, what systems are vulnerable?

Crew TV
Your answer
Engine room
Your answer
Navigation bridge
Your answer
Personal CO2 monitors
Your answer

As an organisation, I must always appoint a Data Processing Officer. Is this statement true or false?

True
Your answer
False
Your answer

The advantage of the 'NIST framework' lies in its local application and exactingness, which is why it can be employed in many industries, including the maritime one. Is this statement true or false?

True
Your answer
False
Your answer

The NIST framework covers five areas that are essential for a successful cybersecurity framework. Which of the following is not part of these five areas?

Response
Your answer
Identification
Your answer
Protection
Your answer
Installation
Your answer

As a seafarer on board, it doesn´t matter if I use company computers for personal usage. Is this statement true or false?

True
Your answer
False
Your answer

Fill in the sentence: The GDPR sites supervisory authorities the power to issue fines of up to €20 million or __% of the breached organisations annual global turnover.

2
Your answer
4
Your answer
6
Your answer

What is the data subject?

The person who denied why and how personal data would be processed.
Your answer
A third party that process personal data on behalf of a data controller.
Your answer
The person whose data is processed
Your answer

Data Protection Directive (DPD) was replaced with General Data Protection Regulation (GDPR) in what year?

2020
Your answer
2014
Your answer
2018
Your answer
2016
Your answer

What is personal data?

An e-mail address.
Your answer
Anonymised data.
Your answer
Any information related to an identified or identifiable natural person.
Your answer
A registration number of a company.
Your answer

Which of the following is not part of the 7 key principles?

Integrity and confidentiality
Your answer
Purpose limitation
Your answer
Empathy
Your answer
Accuracy
Your answer

When there has been a violation of personal privacy, within what time period are companies obligated to report system violations?

1 month
Your answer
72 hours
Your answer
24 hours
Your answer
1 week
Your answer
Score: Attempts:

Rate Your Experience

Congratulations ! You completed General Data Protection Regulation. Now rate your experience.

Click the stars to rate