Back to dashboard Read module

Quiz reading view

Quiz 1C — EU Frameworks: GDPR, NIS2, and the Budapest Convention

Use this quiz to check whether you can spot the controlling doctrine, procedural hinge, and practical move before treating EU Frameworks: GDPR, NIS2, and the Budapest Convention as learned.

Use this quiz to check whether you can spot the controlling doctrine, procedural hinge, and practical move before treating EU Frameworks: GDPR, NIS2, and the Budapest Convention as learned.

Type Quiz
Updated 2026-04-12
Reading time 5 min read
Questions 10

Check the reading before you move on.

01c-eu-international-frameworks.md | Last updated: 2026-04-12

**DISCLAIMER:** Educational purposes only. Not legal advice.

Question 1

A European hospital that is classified as an "essential entity" under NIS2 experiences a ransomware attack on Monday at 9am. By what time must the hospital submit the NIS2 early warning to its national competent authority?

Question 2

The same hospital confirms that patient records were likely accessed during the attack. When must it notify the data protection authority under GDPR Article 33?

Question 3

A cloud services company with €500 million annual worldwide turnover is classified as an "essential entity" under NIS2. What is the minimum maximum administrative fine the company could face for a serious NIS2 violation?

Question 4

Under GDPR Article 83 (upper tier), what is the maximum fine for a violation involving unlawful processing of personal data on a fundamental rights basis?

Question 5

Which of the following best describes the relationship between NIS2 and GDPR in the context of a ransomware attack on an EU bank that processes customer financial data?

Question 6

Article 35 of the Budapest Convention establishes what mechanism?

Question 7

What does the Budapest Convention's 24/7 contact network allow investigators to do that the formal MLAT process does NOT provide quickly?

Question 8

Under NIS2, what is the reporting sequence for a significant ongoing cyber incident?

Question 9

The Second Additional Protocol to the Budapest Convention, signed by the U.S. in 2022, primarily addresses which limitation of the original Convention?

Question 10

A GDPR data controller notified the supervisory authority of a breach within 72 hours, but the initial notification was incomplete because the full scope wasn't known. Under GDPR, what should the controller do?