Practice GDPR vocabulary: data subject, data controller vs. processor, lawful basis for processing, DSAR, right to erasure, and Data Protection Authority concepts.
0 / 26 completed
1 / 26
Under GDPR, what is a 'data subject'?
A data subject is the individual whose personal data is being collected or processed. For example, a customer whose name and email are stored in your system is a data subject under GDPR.
2 / 26
What is the difference between a 'data controller' and a 'data processor' under GDPR?
The data controller decides why and how personal data is processed. The data processor handles data only on the controller's instructions — for example, a cloud provider processing data for your company is a processor.
3 / 26
A user submits a 'DSAR.' What are they requesting?
A Data Subject Access Request (DSAR) is a formal request by an individual exercising their GDPR right to access the personal data an organization holds about them, including how and why it is processed.
4 / 26
What is 'legitimate interest' as a lawful basis for GDPR data processing?
Legitimate interest is one of six lawful bases under GDPR. It allows processing when the controller has a genuine, proportionate reason that is not overridden by the individual's privacy rights — requiring a balancing test.
5 / 26
A customer invokes their 'right to erasure.' What must the organization do?
The right to erasure (also called 'right to be forgotten') requires organizations to delete personal data when, for example, the data is no longer necessary for its original purpose or the person withdraws consent — subject to certain legal exceptions.
6 / 26
Sarah, a junior developer on the team, is reviewing a new PR that collects user email addresses for marketing purposes. During the review, her senior colleague, Mark, suggests adding a checkbox to the form allowing users to opt-out. Sarah asks, 'Is it okay to ask for consent like this? What are our obligations regarding GDPR?'
Explicit consent is a key requirement under GDPR when collecting personal data for marketing. The checkbox Mark suggests fulfills this by providing users with the ability to affirmatively agree to receiving emails. Simply stating terms of service doesn't constitute valid consent; it must be actively given. This demonstrates a crucial understanding of how to handle user data and requests for information.
7 / 26
Mark: "Okay, Sarah, adding a checkbox for opt-out is a good step. It demonstrates we're respecting user choices and helps us comply with GDPR. We should also ensure the terms and conditions clearly explain how we use their data."
While adding an opt-out checkbox is a positive step towards GDPR compliance, it's not sufficient on its own. GDPR requires more than just a simple mechanism for users to withdraw consent; you must also have clear and accessible documentation explaining data usage, regularly review consent records, and ensure the process aligns with principles like transparency and user control. The key is demonstrating a proactive approach to fulfilling data subject rights.
8 / 26
PR Description
Subject: Implement new user onboarding flow - collect email for welcome series.
Details:
"This PR introduces a form to capture users' email addresses upon signup. We'll then use this data to send a personalized welcome series of emails, increasing engagement and driving product adoption. No other personally identifiable information is collected."
This question tests understanding of GDPR's requirements around consent. Simply stating that data is collected isn't enough; the PR needs to highlight the purpose (marketing emails) and demonstrate how explicit consent is being obtained – in this case, through an opt-in checkbox. Option A is incorrect because it focuses on a missing legal requirement without considering the practical application of GDPR. Option C is wrong as it misunderstands that the description itself needs to address consent, not just the email content.
9 / 26
David, a senior backend engineer, is reviewing a pull request submitted by Ben. The PR includes an API endpoint that allows users to update their profile information, including their address and phone number. Ben's comment reads: 'Just added the ability for users to update their contact details via this new API. It should improve data accuracy.'
Which of the following statements best reflects David's likely concern regarding GDPR compliance?
The key here is understanding that even seemingly innocuous actions can raise GDPR concerns. While Ben's comment isn't *wrong* technically (the API exists), it lacks crucial context regarding the lawful basis for processing this data—specifically, consent or another legitimate basis. The incorrect options focus on overly specific elements like 'data minimization' or a missing 'consent clause,' which aren't necessarily the immediate concern. David's likely worry is that Ben hasn't considered *why* they are collecting this information and how it will be handled, leading to potential non-compliance with GDPR's data protection principles.
10 / 26
Sarah, a junior developer on the team, is reviewing a new PR that collects user email addresses for marketing purposes. During the review, her senior colleague, Mark, suggests adding a checkbox to the form allowing users to opt-out. Sarah asks, 'Is it okay to ask for consent like this? What are our obligations regarding GDPR?'
Explicit consent is a key requirement under GDPR when collecting personal data for marketing. The checkbox Mark suggests fulfills this by providing users with the ability to affirmatively agree to receiving emails. Simply stating terms of service doesn't constitute valid consent; it must be actively given. This demonstrates a crucial understanding of how to handle user data and requests for information.
11 / 26
Mark: "Okay, Sarah, adding a checkbox for opt-out is a good step. It demonstrates we're respecting user choices and helps us comply with GDPR. We should also ensure the terms and conditions clearly explain how we use their data."
While adding an opt-out checkbox is a positive step towards GDPR compliance, it's not sufficient on its own. GDPR requires more than just a simple mechanism for users to withdraw consent; you must also have clear and accessible documentation explaining data usage, regularly review consent records, and ensure the process aligns with principles like transparency and user control. The key is demonstrating a proactive approach to fulfilling data subject rights.
12 / 26
PR Description
Subject: Implement new user onboarding flow - collect email for welcome series.
Details:
"This PR introduces a form to capture users' email addresses upon signup. We'll then use this data to send a personalized welcome series of emails, increasing engagement and driving product adoption. No other personally identifiable information is collected."
This question tests understanding of GDPR's requirements around consent. Simply stating that data is collected isn't enough; the PR needs to highlight the purpose (marketing emails) and demonstrate how explicit consent is being obtained – in this case, through an opt-in checkbox. Option A is incorrect because it focuses on a missing legal requirement without considering the practical application of GDPR. Option C is wrong as it misunderstands that the description itself needs to address consent, not just the email content.
13 / 26
David, a senior backend engineer, is reviewing a pull request submitted by Ben. The PR includes an API endpoint that allows users to update their profile information, including their address and phone number. Ben's comment reads: 'Just added the ability for users to update their contact details via this new API. It should improve data accuracy.'
Which of the following statements best reflects David's likely concern regarding GDPR compliance?
The key here is understanding that even seemingly innocuous actions can raise GDPR concerns. While Ben's comment isn't *wrong* technically (the API exists), it lacks crucial context regarding the lawful basis for processing this data—specifically, consent or another legitimate basis. The incorrect options focus on overly specific elements like 'data minimization' or a missing 'consent clause,' which aren't necessarily the immediate concern. David's likely worry is that Ben hasn't considered *why* they are collecting this information and how it will be handled, leading to potential non-compliance with GDPR's data protection principles.
14 / 26
Sarah, a junior developer on the team, is reviewing a new PR that collects user email addresses for marketing purposes. During the review, her senior colleague, Mark, suggests adding a checkbox to the form allowing users to opt-out. Sarah asks, 'Is it okay to ask for consent like this? What are our obligations regarding GDPR?'
Explicit consent is a key requirement under GDPR when collecting personal data for marketing. The checkbox Mark suggests fulfills this by providing users with the ability to affirmatively agree to receiving emails. Simply stating terms of service doesn't constitute valid consent; it must be actively given. This demonstrates a crucial understanding of how to handle user data and requests for information.
15 / 26
Mark: "Okay, Sarah, adding a checkbox for opt-out is a good step. It demonstrates we're respecting user choices and helps us comply with GDPR. We should also ensure the terms and conditions clearly explain how we use their data."
While adding an opt-out checkbox is a positive step towards GDPR compliance, it's not sufficient on its own. GDPR requires more than just a simple mechanism for users to withdraw consent; you must also have clear and accessible documentation explaining data usage, regularly review consent records, and ensure the process aligns with principles like transparency and user control. The key is demonstrating a proactive approach to fulfilling data subject rights.
16 / 26
PR Description
Subject: Implement new user onboarding flow - collect email for welcome series.
Details:
"This PR introduces a form to capture users' email addresses upon signup. We'll then use this data to send a personalized welcome series of emails, increasing engagement and driving product adoption. No other personally identifiable information is collected."
This question tests understanding of GDPR's requirements around consent. Simply stating that data is collected isn't enough; the PR needs to highlight the purpose (marketing emails) and demonstrate how explicit consent is being obtained – in this case, through an opt-in checkbox. Option A is incorrect because it focuses on a missing legal requirement without considering the practical application of GDPR. Option C is wrong as it misunderstands that the description itself needs to address consent, not just the email content.
17 / 26
David, a senior backend engineer, is reviewing a pull request submitted by Ben. The PR includes an API endpoint that allows users to update their profile information, including their address and phone number. Ben's comment reads: 'Just added the ability for users to update their contact details via this new API. It should improve data accuracy.'
Which of the following statements best reflects David's likely concern regarding GDPR compliance?
The key here is understanding that even seemingly innocuous actions can raise GDPR concerns. While Ben's comment isn't *wrong* technically (the API exists), it lacks crucial context regarding the lawful basis for processing this data—specifically, consent or another legitimate basis. The incorrect options focus on overly specific elements like 'data minimization' or a missing 'consent clause,' which aren't necessarily the immediate concern. David's likely worry is that Ben hasn't considered *why* they are collecting this information and how it will be handled, leading to potential non-compliance with GDPR's data protection principles.
18 / 26
Sarah, a junior developer on the team, is reviewing a new PR that collects user email addresses for marketing purposes. During the review, her senior colleague, Mark, suggests adding a checkbox to the form allowing users to opt-out. Sarah asks, 'Is it okay to ask for consent like this? What are our obligations regarding GDPR?'
Explicit consent is a key requirement under GDPR when collecting personal data for marketing. The checkbox Mark suggests fulfills this by providing users with the ability to affirmatively agree to receiving emails. Simply stating terms of service doesn't constitute valid consent; it must be actively given. This demonstrates a crucial understanding of how to handle user data and requests for information.
19 / 26
Mark: "Okay, Sarah, adding a checkbox for opt-out is a good step. It demonstrates we're respecting user choices and helps us comply with GDPR. We should also ensure the terms and conditions clearly explain how we use their data."
While adding an opt-out checkbox is a positive step towards GDPR compliance, it's not sufficient on its own. GDPR requires more than just a simple mechanism for users to withdraw consent; you must also have clear and accessible documentation explaining data usage, regularly review consent records, and ensure the process aligns with principles like transparency and user control. The key is demonstrating a proactive approach to fulfilling data subject rights.
20 / 26
PR Description
Subject: Implement new user onboarding flow - collect email for welcome series.
Details:
"This PR introduces a form to capture users' email addresses upon signup. We'll then use this data to send a personalized welcome series of emails, increasing engagement and driving product adoption. No other personally identifiable information is collected."
This question tests understanding of GDPR's requirements around consent. Simply stating that data is collected isn't enough; the PR needs to highlight the purpose (marketing emails) and demonstrate how explicit consent is being obtained – in this case, through an opt-in checkbox. Option A is incorrect because it focuses on a missing legal requirement without considering the practical application of GDPR. Option C is wrong as it misunderstands that the description itself needs to address consent, not just the email content.
21 / 26
David, a senior backend engineer, is reviewing a pull request submitted by Ben. The PR includes an API endpoint that allows users to update their profile information, including their address and phone number. Ben's comment reads: 'Just added the ability for users to update their contact details via this new API. It should improve data accuracy.'
Which of the following statements best reflects David's likely concern regarding GDPR compliance?
The key here is understanding that even seemingly innocuous actions can raise GDPR concerns. While Ben's comment isn't *wrong* technically (the API exists), it lacks crucial context regarding the lawful basis for processing this data—specifically, consent or another legitimate basis. The incorrect options focus on overly specific elements like 'data minimization' or a missing 'consent clause,' which aren't necessarily the immediate concern. David's likely worry is that Ben hasn't considered *why* they are collecting this information and how it will be handled, leading to potential non-compliance with GDPR's data protection principles.
22 / 26
During a code review of a new feature that allows users to subscribe to newsletters, David comments to Ben: 'I'm concerned about the data retention policy here. We need to ensure we're only storing email addresses for as long as necessary and have a clear process for unsubscribes. Does this align with our GDPR strategy?' Which of the following best captures David's concern?
David's comment focuses on the crucial aspect of GDPR – data minimization and retention. He specifically highlights the need for a defined schedule for deleting user data and a process for handling opt-outs, demonstrating an understanding that simply collecting emails isn't enough; compliance requires proactive management of their lifecycle. Options A, C, and D address tangential issues.
23 / 26
Lena sends the following message in a Slack channel: 'Just deployed the new analytics tracking – collecting user IDs and session data. Need to ensure we're compliant with GDPR's consent requirements for this type of data collection.' What's the *primary* issue Lena is raising?
The core of Lena's message is about GDPR consent. Collecting user IDs and session data falls under GDPR's definition of 'personal data,' and therefore requires explicit consent from the users before collection. Options A, B, and C represent secondary concerns that could arise as a result of not addressing the fundamental consent issue.
24 / 26
PR Description
Subject: Implement user preference center.
Details:
"This PR introduces a new interface where users can manage their communication preferences. We're collecting email addresses to send promotional offers and updates. We've added a checkbox to opt-out, but haven't defined how long we retain this data. What is the MOST important thing to add to the description to ensure GDPR compliance?
While a privacy policy is important, the *most* crucial element for GDPR compliance in this scenario is explicitly stating how long user data will be retained and outlining the opt-out process. This directly addresses Article 5(1)(e) of GDPR – limiting processing to what's necessary for specified purposes. Options A, B, and C are less critical to immediate compliance.
25 / 26
The following is an API response from a user profile update endpoint:
{
"status": "success",
"user_id": "12345",
"email": "john.doe@example.com",
"address": "1 Main St"
}
What potential GDPR issue is present in this response, and what action should be taken to mitigate it?
GDPR emphasizes data minimization. Returning the user's address alongside their email and ID is likely unnecessary and constitutes a potential breach of privacy regulations. The response should be modified to only include essential information for profile updates (e.g., just the email address). Options A, B, and C are unrelated issues.
26 / 26
"Mark: 'I'm working on implementing a new consent management system for our users. We need to ensure we're compliant with GDPR when collecting and processing user data.' What is Mark primarily focusing on?
Mark's update explicitly mentions 'GDPR compliance,' indicating his primary focus is on ensuring that the consent management system adheres to the regulations surrounding data collection and processing. Options A, B, C, and D represent secondary tasks related to the implementation or usage of the system.
What does the "GDPR Vocabulary Quiz" exercise practise?
Practice GDPR vocabulary: data subject, data controller vs. processor, lawful basis for processing, DSAR, right to erasure, and Data Protection Authority concepts.
How many questions are in this exercise?
This exercise has 26 questions, each multiple-choice with a full explanation shown after you answer.
What English level is this exercise for?
This exercise is tagged Intermediate. If the vocabulary feels difficult, browse the Compliance Security category page for an easier module to start with.
Is this exercise free to use?
Yes. Every exercise on CoderSlingo, including this one, is free with no account, sign-up, or paywall.
Do I get feedback if I answer incorrectly?
Yes — whichever option you choose, right or wrong, you'll immediately see an explanation clarifying the correct term and why the other options don't fit.
Can I retry this exercise?
Yes — once you finish all the questions, a "Try again" button on the results screen resets the exercise so you can practise as many times as you like.
Do I need an account to track my progress?
No account is required. Your progress bar and score for this session are tracked in the browser as you go, but nothing is saved once you leave the page.
Is "GDPR Vocabulary Quiz" part of a larger series?
Yes — it's one exercise in the Compliance Security category on CoderSlingo. See the category page for the full list of related exercises on similar terminology.
Can I link directly to this exercise?
Yes — this exercise has its own permanent URL, so you can bookmark it or share the link directly with a colleague or study partner.
Where can I find more exercises like this one?
See the Compliance Security category page for related exercises, or browse the main Exercises hub for other IT English topics.