Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

IAPP CIPP-E Exam - Topic 2 Question 127 Discussion

After detecting an intrusion involving the theft of unencrypted personal data, who shall the breached company notify first under GDPR requirements?
B) Any affected customers whose data was compromised.
A) Any parents of children whose personal data was compromised.
C) A competent supervisory authority.
D) A local law enforcement agency

IAPP CIPP-E Exam - Topic 2 Question 127 Discussion

Actual exam question for IAPP's CIPP-E exam
Question #: 127
Topic #: 2
[All CIPP-E Questions]

After detecting an intrusion involving the theft of unencrypted personal data, who shall the breached company notify first under GDPR requirements?

Show Suggested Answer Hide Answer
Suggested Answer: B

Contribute your Thoughts:

0/2000 characters
Elin
15 hours ago
Nope, it’s definitely the supervisory authority.
upvoted 0 times
...
Letha
6 days ago
Wait, are you sure? I thought it was the customers first.
upvoted 0 times
...
Ula
11 days ago
I agree, it’s all about reporting to the authority first!
upvoted 0 times
...
Kanisha
16 days ago
Definitely C) A competent supervisory authority. That's the rule.
upvoted 0 times
...
Arletta
21 days ago
From what I studied, the GDPR emphasizes notifying the supervisory authority first, but I could be mixing it up with other regulations.
upvoted 0 times
...
Rozella
26 days ago
I’m a bit confused; I thought they had to inform law enforcement before anyone else, but that might not be right.
upvoted 0 times
...
Flo
1 month ago
I remember practicing a similar question, and I believe it's about notifying affected customers after the authority.
upvoted 0 times
...
Lorenza
1 month ago
I think the company has to notify the supervisory authority first, but I'm not completely sure.
upvoted 0 times
...

Save Cancel