Practise GDPR data subject rights vocabulary: right to access, erasure, portability, rectification, and restriction.
0 / 14 completed
1 / 14
Under GDPR, the 'right to erasure' (right to be forgotten) allows data subjects to request:
The right to erasure (Article 17) allows deletion when the original purpose is fulfilled, consent is withdrawn, or processing is unlawful — subject to some exceptions (legal obligations, public interest).
2 / 14
A GDPR 'Data Subject Access Request' (DSAR) entitles the individual to receive:
A DSAR response must include: a copy of the personal data, the processing purposes, retention periods, recipient categories, and information about data subject rights.
3 / 14
GDPR 'data minimisation' means:
Data minimisation (Article 5) is a core GDPR principle: collect only what you need for the stated purpose. Collecting additional data just in case is a GDPR violation.
4 / 14
Under GDPR, a 'processor' is:
A processor acts on the controller's instructions (e.g., a cloud service, payroll provider). Processors have specific GDPR obligations including entering into a Data Processing Agreement.
5 / 14
GDPR requires notification of a personal data breach to the supervisory authority within:
GDPR Article 33 requires breach notification to the supervisory authority within 72 hours if the breach is likely to result in a risk to individuals' rights and freedoms.
6 / 14
Sarah from the frontend team is reviewing a pull request for a new user profile feature. The PR includes collecting and storing email addresses to personalize recommendations. During the review, she notices a comment from Mark in the Slack channel: 'Just make sure we're complying with GDPR – we need to give users the option to opt-out.' Which of the following best describes Mark's concern?
Mark is correctly referencing the GDPR's 'right to object' – more precisely, the user's right to prevent their data from being used for direct marketing and personalized recommendations. While a DSAR allows users to access and delete *all* of their data, this particular comment focuses on limiting the use of email addresses for targeted advertising. The other options represent different technical or administrative concerns, but don't directly address the core GDPR right Mark is referencing.
7 / 14
Sarah from the frontend team is reviewing a pull request for a new user profile feature. The PR includes collecting and storing email addresses to personalize recommendations. During the review, she notices a comment from Mark in the Slack channel: 'Just make sure we're complying with GDPR – we need to give users the option to opt-out.' Which of the following best describes Mark's concern?
Mark is correctly referencing the GDPR's 'right to object' – more precisely, the user's right to prevent their data from being used for direct marketing and personalized recommendations. While a DSAR allows users to access and delete *all* of their data, this particular comment focuses on limiting the use of email addresses for targeted advertising. The other options represent different technical or administrative concerns, but don't directly address the core GDPR right Mark is referencing.
8 / 14
Sarah from the frontend team is reviewing a pull request for a new user profile feature. The PR includes collecting and storing email addresses to personalize recommendations. During the review, she notices a comment from Mark in the Slack channel: 'Just make sure we're complying with GDPR – we need to give users the option to opt-out.' Which of the following best describes Mark's concern?
Mark is correctly referencing the GDPR's 'right to object' – more precisely, the user's right to prevent their data from being used for direct marketing and personalized recommendations. While a DSAR allows users to access and delete *all* of their data, this particular comment focuses on limiting the use of email addresses for targeted advertising. The other options represent different technical or administrative concerns, but don't directly address the core GDPR right Mark is referencing.
9 / 14
Sarah from the frontend team is reviewing a pull request for a new user profile feature. The PR includes collecting and storing email addresses to personalize recommendations. During the review, she notices a comment from Mark in the Slack channel: 'Just make sure we're complying with GDPR – we need to give users the option to opt-out.' Which of the following best describes Mark's concern?
Mark is correctly referencing the GDPR's 'right to object' – more precisely, the user's right to prevent their data from being used for direct marketing and personalized recommendations. While a DSAR allows users to access and delete *all* of their data, this particular comment focuses on limiting the use of email addresses for targeted advertising. The other options represent different technical or administrative concerns, but don't directly address the core GDPR right Mark is referencing.
10 / 14
Mark, the DevOps engineer, is drafting a Slack message to inform the team about a potential GDPR compliance issue. The new microservice collects user location data for analytics purposes. He writes: 'We're just gathering some location info to get a better understanding of our users.' Which phrase best reflects Mark's understanding of data minimisation in this context?
Data minimisation requires collecting only the data absolutely necessary for a specific purpose. Mark's original statement suggests gathering 'all available data,' which contradicts this principle. Option 1 correctly identifies that he's focusing on 'minimum necessary location data' – the key to GDPR compliance.
11 / 14
Elena, a security analyst, is reviewing a pull request description for a new feature that allows users to opt out of personalized email marketing. The PR includes the following text: 'This will enhance user engagement by sending targeted emails.' Which statement accurately reflects Elena's understanding of a right to object under GDPR?
The right to object grants individuals the power to refuse processing of their personal data, particularly for direct marketing. Elena's role is to ensure compliance, and the PR description fails to acknowledge this fundamental right. Option 1 highlights the crucial element – that users must be able to opt out.
12 / 14
David, a developer, is responding to a code review comment regarding user data storage. The comment states: 'Ensure all personal data is pseudonymized before storing it.' What does 'pseudonymization' primarily achieve in relation to GDPR?
Pseudonymization involves substituting direct identifiers (like names or email addresses) with artificial representations. This significantly reduces the risk of identifying individuals if the pseudonymized data is compromised—it doesn't make it anonymous, but it limits potential harm. Option 1 misrepresents the process.
13 / 14
Jessica, a product manager, needs to explain GDPR's requirements to her team during a standup meeting. Which of the following best describes what a 'data processor' is in the context of GDPR?
Under GDPR, a 'data processor' is an entity that processes personal data on behalf of another organization (the 'controller'). This includes cloud providers, marketing automation platforms, and any third-party service handling user data. Option 2 accurately defines this crucial role.
14 / 14
Tom, a lead developer, is investigating a reported GDPR breach. The company's records show that customer data was exposed due to an unpatched vulnerability. According to GDPR regulations, how quickly must the company notify the relevant supervisory authority?
GDPR mandates notification of a personal data breach to the supervisory authority within 72 hours of becoming aware of the breach. This timeframe is strict and designed to allow authorities to investigate and mitigate potential harm. Option 1 correctly identifies this critical requirement.
What does the "GDPR Rights Vocabulary" exercise practise?
Practise GDPR data subject rights vocabulary: right to access, erasure, portability, rectification, and restriction.
How many questions are in this exercise?
This exercise has 14 questions, each multiple-choice with a full explanation shown after you answer.
What English level is this exercise for?
This exercise is tagged Intermediate. If the vocabulary feels difficult, browse the Data Privacy category page for an easier module to start with.
Is this exercise free to use?
Yes. Every exercise on CoderSlingo, including this one, is free with no account, sign-up, or paywall.
Do I get feedback if I answer incorrectly?
Yes — whichever option you choose, right or wrong, you'll immediately see an explanation clarifying the correct term and why the other options don't fit.
Can I retry this exercise?
Yes — once you finish all the questions, a "Try again" button on the results screen resets the exercise so you can practise as many times as you like.
Do I need an account to track my progress?
No account is required. Your progress bar and score for this session are tracked in the browser as you go, but nothing is saved once you leave the page.
Is "GDPR Rights Vocabulary" part of a larger series?
Yes — it's one exercise in the Data Privacy category on CoderSlingo. See the category page for the full list of related exercises on similar terminology.
Can I link directly to this exercise?
Yes — this exercise has its own permanent URL, so you can bookmark it or share the link directly with a colleague or study partner.
Where can I find more exercises like this one?
See the Data Privacy category page for related exercises, or browse the main Exercises hub for other IT English topics.