CREST Practitioner Security Analyst (CPSA) Practice

Disable ads (and more) with a membership for a one time $2.99 payment

Master the CREST Practitioner Security Analyst Exam. Prepare with quizzes and comprehensive study guides that include tips and explanations. Excel in your certification journey!

Each practice test/flash card set has 50 randomly selected questions from a bank of over 500. You'll get a new set of questions each time!

Practice this question and more.


Which of the following acts is referred to as GDPR for the UK?

  1. Data Protection Act 1998

  2. Computer Misuse Act 1990

  3. Human Rights Act 1998

  4. Freedom of Information Act 2000

The correct answer is: Data Protection Act 1998

The Data Protection Act 1998 corresponds to the framework established for data protection in the UK prior to the introduction of the General Data Protection Regulation (GDPR). However, it's important to note that while the Data Protection Act 1998 was in effect, it was replaced by the Data Protection Act 2018, which implements the GDPR into UK law. This new legislation builds upon the principles set out in the GDPR and adapts them for the context of UK law following Brexit. Therefore, while the Data Protection Act 1998 is not currently in line with GDPR standards, it is the legislation that initially established data protection rights in the UK. The other options listed represent different areas of law that do not directly pertain to data protection. The Computer Misuse Act focuses on computer-related offenses, the Human Rights Act pertains to human rights legislation, and the Freedom of Information Act deals with access to information held by public authorities. These laws serve different purposes and are not directly related to data protection in the context of GDPR.