Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

IAPP CIPP-E Exam - Topic 2 Question 90 Discussion

Actual exam question for IAPP's CIPP-E exam
Question #: 90
Topic #: 2
[All CIPP-E Questions]

Pursuant to the EDPB Guidelines 8/2022, all of the following criteria must be considered when identifying a lead supervisory authority of a controller EXCEPT?

Show Suggested Answer Hide Answer
Suggested Answer: C

According to the GDPR, the material scope of the regulation covers the processing of personal data wholly or partly by automated means, or by non-automated means if the data forms part of a filing system or is intended to form part of a filing system (Article 2(1)). Personal data is defined as any information relating to an identified or identifiable natural person (data subject) (Article 4(1)). An identifiable natural person is one who can be identified, directly or indirectly, by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person (Article 4(1)). Therefore, pseudonymous data, such as blockchain transactions that use public keys or other identifiers, may still fall within the definition of personal data if the data subject can be identified or re-identified by using additional information or means (Recital 26).

The GDPR also applies to the processing of personal data in the context of the activities of an establishment of a controller or a processor in the European Union, regardless of whether the processing takes place in the European Union or not (Article 3(1)). The GDPR also applies to the processing of personal data of data subjects who are in the European Union by a controller or processor not established in the European Union, where the processing activities are related to the offering of goods or services to such data subjects in the European Union or the monitoring of their behaviour as far as their behaviour takes place within the European Union (Article 3(2)). Therefore, the territorial scope of the GDPR covers both controllers and processors established in the European Union, and controllers and processors not established in the European Union but targeting or monitoring data subjects in the European Union.

In this scenario, blockchain transactions are classified as pseudonymous data, which may still be considered as personal data under the GDPR if the data subjects can be identified or re-identified. Therefore, such transactions are within the material scope of the GDPR, as they involve the processing of personal data by automated means. However, the GDPR only applies to such transactions to the extent that they include data subjects in the European Union, either by having a controller or processor established in the European Union, or by offering goods or services to or monitoring the behaviour of such data subjects. Therefore, the answer is C.


Contribute your Thoughts:

0/2000 characters
Asha
4 months ago
Totally agree, C doesn’t fit with the others!
upvoted 0 times
...
Dana
4 months ago
Wait, can the controller really choose their own authority? That seems off.
upvoted 0 times
...
Shawnda
4 months ago
B seems pretty straightforward, but I’m not sure about D.
upvoted 0 times
...
Rory
4 months ago
I think C is the odd one out here.
upvoted 0 times
...
Lanie
4 months ago
A is definitely a key factor in identifying the lead authority.
upvoted 0 times
...
Joanna
5 months ago
I thought the focus was on the central administration and decision-making locations, so maybe option B is the odd one out?
upvoted 0 times
...
Gerald
5 months ago
I feel like all the options are related to the EDPB guidelines, but I can't recall if determining the authority for complaints is actually a criterion.
upvoted 0 times
...
Alonzo
5 months ago
I remember practicing a question similar to this, and I think option C might be the one that doesn't fit with the criteria.
upvoted 0 times
...
Ena
5 months ago
I think the lead supervisory authority is mainly about where the controller's central administration is located, but I'm not sure if that applies to all cases.
upvoted 0 times
...
Lavera
5 months ago
This is a tricky one. I'll make sure to read the question and answer choices closely, and eliminate the options that don't match the criteria.
upvoted 0 times
...
Rosio
5 months ago
Okay, let me think this through step-by-step. I need to consider all the listed criteria and determine which one is the exception.
upvoted 0 times
...
Nancey
5 months ago
Hmm, I'm a bit unsure about this one. I'll need to carefully review the EDPB Guidelines 8/2022 to make sure I understand all the relevant criteria.
upvoted 0 times
...
Lelia
5 months ago
This question seems straightforward, I'm pretty confident I can identify the correct criteria that is not considered.
upvoted 0 times
...
Kenneth
5 months ago
I've reviewed the guidelines before, so I think I have a good handle on this. I'll just need to double-check my understanding of the criteria.
upvoted 0 times
...
Roy
6 months ago
I'm a bit unsure about this one. I know the csv module has some quoting constants, but I can't recall which one is the default.
upvoted 0 times
...
Tarra
10 months ago
Haha, I wonder if the humorous answer would be 'Determining if the controller has a good sense of humor.' But I guess that's not actually a criteria in the guidelines.
upvoted 0 times
Shanice
9 months ago
C) Determining the supervisory authority according to what has been identified by the controller as the authority to which data subjects can lodge complaints.
upvoted 0 times
...
Nan
9 months ago
B) Determining the supervisory authority where the place of central administration of the controller is located.
upvoted 0 times
...
Martin
10 months ago
A) Determining where the controller has its place of central administration in the EEA.
upvoted 0 times
...
...
Portia
11 months ago
Ah, I see. The EDPB guidelines are all about determining the lead supervisory authority, not just listening to the controller. This is tricky!
upvoted 0 times
Bea
9 months ago
C) Determining the supervisory authority according to what has been identified by the controller as the authority to which data subjects can lodge complaints.
upvoted 0 times
...
Buck
10 months ago
B) Determining the supervisory authority where the place of central administration of the controller is located.
upvoted 0 times
...
Marylyn
10 months ago
A) Determining where the controller has its place of central administration in the EEA.
upvoted 0 times
...
...
France
11 months ago
I bet the correct answer is something about the 'place of central administration.' That's usually the key in these data protection questions.
upvoted 0 times
Olen
9 months ago
D) Determining if decisions on the processing are taken in another establishment in the EEA, and if that establishment has the power to implement those decisions.
upvoted 0 times
...
Jaime
10 months ago
C) Determining the supervisory authority according to what has been identified by the controller as the authority to which data subjects can lodge complaints.
upvoted 0 times
...
Izetta
10 months ago
B) Determining the supervisory authority where the place of central administration of the controller is located.
upvoted 0 times
...
Monte
11 months ago
A) Determining where the controller has its place of central administration in the EEA.
upvoted 0 times
...
...
Nichelle
11 months ago
Hmm, option C seems too easy. The EDPB guidelines must have more to it than just what the controller says, right?
upvoted 0 times
Wei
10 months ago
B) Determining the supervisory authority where the place of central administration of the controller is located.
upvoted 0 times
...
Keneth
10 months ago
A) Determining where the controller has its place of central administration in the EEA.
upvoted 0 times
...
...
Omega
11 months ago
But the guidelines specifically mention that D is not a criteria to consider.
upvoted 0 times
...
Christiane
11 months ago
I disagree, I believe the answer is A.
upvoted 0 times
...
Omega
11 months ago
I think the answer is D.
upvoted 0 times
...

Save Cancel