Data Privacy Vocabulary Quiz
12 multiple-choice questions on data privacy and GDPR vocabulary: personal data, consent, data controller, data breach, encryption, pseudonymisation and the right to erasure. B2 level.
This quiz focuses on how the target vocabulary for Data Privacy is actually used in context at B2 level, rather than testing bare definitions. Correct answers you will need to identify include terms such as GDPR, personal, controller, processor and breach, each embedded in a full example sentence so you have to judge meaning from context, not just recognise an isolated word.
Working through all 12 questions and checking the explanations in the FAQ below is a quick way to spot any terms you are still unsure of. Revisiting the quiz again after a day or two, rather than only once, is one of the most reliable ways to move new vocabulary from passive recognition into words you can use confidently yourself in speaking and writing.
Keep building your data privacy vocabulary.
Data Privacy Vocabulary — FAQ
What is the GDPR?
The GDPR (General Data Protection Regulation) is a comprehensive data protection law introduced by the EU in May 2018. It sets out rules for how organisations must collect, store and protect personal data. It applies to any organisation handling EU residents' data. Fines for serious breaches can reach 4% of global annual turnover or €20 million.
What is 'personal data' under the GDPR?
Personal data is any information that relates to an identified or identifiable living individual. This includes names, email addresses and location data, but also IP addresses and cookie identifiers. Special categories of sensitive data, such as health information or racial origin, receive additional protection.
What does 'consent' mean in data privacy?
Consent is one of the lawful bases for processing personal data. For it to be valid under the GDPR, it must be freely given, specific, informed and unambiguous — the individual must actively opt in. People must also be able to withdraw consent at any time as easily as they gave it.
What is a 'data controller' versus a 'data processor'?
A data controller determines the purposes and means of processing personal data. A data processor is a third party that processes data on behalf of the controller, such as a cloud provider. Controllers have primary legal responsibility; processors must act only on documented instructions from the controller.
What is a 'data breach'?
A data breach is a security incident in which personal data is accidentally or unlawfully accessed or disclosed. Under the GDPR, organisations must report a breach to their supervisory authority within 72 hours of becoming aware of it, if it poses a risk to individuals' rights.
What is 'encryption'?
Encryption converts data into a coded form readable only by someone with the correct decryption key. It is a key technical safeguard recommended by the GDPR. If encrypted data is breached, it is unreadable to an attacker.
What is 'pseudonymisation'?
Pseudonymisation processes personal data so it can no longer be attributed to a specific individual without additional, separately held information (e.g. replacing a name with a reference number). The GDPR encourages this as a privacy-enhancing measure, but pseudonymised data is still personal data since re-identification is possible.
What is the 'right to erasure'?
The right to erasure (right to be forgotten) allows individuals to request deletion of their personal data in certain circumstances — for example, when data is no longer necessary or consent is withdrawn. Organisations must respond within one month. The right is not absolute and does not apply when data must be kept for legal compliance.
What is a 'privacy notice'?
A privacy notice explains to individuals how their personal data is collected, used, stored and shared. Under the GDPR it must be written in plain language and include the lawful basis for processing, retention period and individuals' rights. It must be provided at the time personal data is collected.
What is 'data minimisation'?
Data minimisation is a GDPR principle requiring organisations to collect only personal data that is adequate, relevant and limited to what is necessary for the stated purpose. It reduces the risk to individuals if a breach occurs and helps build trust with customers.