Make My Jeopardy

Data Privacy and GDPR Jeopardy

Personal data, lawful bases, subject access requests, and breach deadlines, turned into a quiz. Copy the board free and let your team buzz in from their phones.

6 categories · 30 clues · Final Jeopardy · everyone buzzes in from their phone

For work

Copies all 30 clues into an editor of your own. Free, no account needed.

Every clue on this board

This page is public, so anyone can read the answers — copy the board and swap a few clues before game day.

What Counts as Personal Data

  1. $200

    Though it is just a string of numbers, this address assigned to a device online can count as personal data under the GDPR.

    What is an IP address?

  2. $400

    Health, religion and ethnic origin fall into this GDPR category of data that needs extra protection.

    What is special category data?

  3. $600

    Fingerprints and facial scans used to identify someone are this type of special category data.

    What is biometric data?

  4. $800

    Replacing names with codes while keeping a separate key to re-identify people is this technique, and the data stays personal.

    What is pseudonymisation?

  5. $1,000

    Data that has been processed so that nobody can reasonably be identified from it falls outside the GDPR as this.

    What is anonymised data?

Lawful Bases for Processing

  1. $200

    The GDPR lists this many lawful bases for processing personal data.

    What is six?

  2. $400

    This lawful basis must be freely given, specific, informed and unambiguous.

    What is consent?

  3. $600

    Using a customer's address to deliver the item they ordered relies on this lawful basis.

    What is contract?

  4. $800

    This flexible lawful basis requires a balancing test between an organization's aims and the individual's rights.

    What are legitimate interests?

  5. $1,000

    An employer sending salary details to the tax authority because the law requires it relies on this lawful basis.

    What is legal obligation?

Rights of the Data Subject

  1. $200

    This right, often called the right to be forgotten, lets people ask for their data to be deleted.

    What is the right to erasure?

  2. $400

    A person asking an organization for a copy of the personal data it holds about them is making this three-word request.

    What is a subject access request?

  3. $600

    Organizations generally have this long to respond to a request for access, though it can be extended for complex cases.

    What is one month?

  4. $800

    This right lets people receive their data in a machine-readable format and move it to another provider.

    What is the right to data portability?

  5. $1,000

    Absolute where direct marketing is concerned, this right lets people tell an organization to stop processing their data.

    What is the right to object?

Breaches and Reporting

  1. $200

    Emailing a spreadsheet of customer details to the wrong person counts as this, even with no hacker involved.

    What is a personal data breach?

  2. $400

    Many organizations must appoint this independent role to advise on GDPR compliance and act as the contact for regulators.

    What is a data protection officer?

  3. $600

    When a breach is likely to pose a high risk to people's rights, the organization must also tell these people without undue delay.

    Who are the affected individuals?

  4. $800

    This UK regulator, known by three initials, receives personal data breach reports from British organizations.

    What is the Information Commissioner's Office?

  5. $1,000

    For the most serious infringements, GDPR fines can reach 20 million euros or this share of global annual turnover, whichever is higher.

    What is 4 percent?

Privacy by Design

  1. $200

    Collecting only the personal data you actually need is this principle.

    What is data minimisation?

  2. $400

    The companion to privacy by design, this principle means the most privacy-friendly settings apply automatically.

    What is privacy by default?

  3. $600

    This principle says personal data should be kept for no longer than it is needed.

    What is storage limitation?

  4. $800

    Before starting processing likely to pose a high risk to people, organizations must carry out this assessment.

    What is a data protection impact assessment?

  5. $1,000

    This principle says data collected for one specified reason should not be reused for an incompatible one.

    What is purpose limitation?

Everyday Privacy Habits

  1. $200

    This type of fraudulent email tries to trick staff into revealing passwords or personal data.

    What is phishing?

  2. $400

    Putting recipients in this email field hides their addresses from one another in a group message.

    What is BCC?

  3. $600

    Paper records containing personal data should be destroyed this way rather than put in the regular recycling.

    What is shredding?

  4. $800

    This policy asks staff to clear papers containing personal data off their desks at the end of the day.

    What is a clean desk policy?

  5. $1,000

    Requiring a password plus a code from an app on your phone is this security measure.

    What is multi-factor authentication?

Final Jeopardy — Breach Deadlines

Under the GDPR, a personal data breach must generally be reported to the supervisory authority within this many hours of the organization becoming aware of it.

What is 72 hours?

How to run this board

Privacy rules are easier to follow when people remember why they exist. This board covers what counts as personal data, the lawful bases for processing it, the rights individuals hold over their data, what to do when a breach happens, and the privacy-by-design habits that keep most problems from starting.

It is a refresher for staff who have already done formal data protection training, not a substitute for it or for advice from your data protection officer. Clues stick to the well-established core of the GDPR rather than fine amounts or national variations.

A good house rule: after any clue about a subject access request or a breach, ask the room who they would tell first inside your own organization. The answer is often the most useful thing anyone learns all session.

More from the library

Spotted a clue that's wrong or out of date? Tell us and we'll fix the board. Or start from a blank board and write your own.