Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

IAPP CIPP-E Exam - Topic 5 Question 121 Discussion

Actual exam question for IAPP's CIPP-E exam
Question #: 121
Topic #: 5
[All CIPP-E Questions]

A company has collected personal data tor direct marketing purpose on the basis of consent. It is now considering using this data to develop new products through analytics. What is the company first required to do?

Show Suggested Answer Hide Answer
Suggested Answer: A

According to the GDPR, consent is one of the lawful bases for processing personal data1.Consent means any freely given, specific, informed and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her2.Therefore, consent must be specific to each purpose of processing and cannot be bundled with other purposes3.If a company wants to use personal data for a new purpose that is not compatible with the original purpose for which consent was given, it must obtain a new consent from the data subjects for the new processing4. Simply informing the data subjects of the new purpose or updating the privacy notice is not sufficient, as it does not imply the data subject's agreement to the new processing.Proceeding with the new processing without obtaining a new consent would be unlawful and could result in fines and sanctions5.Reference:

Free CIPP/E Study Guide, page 23, section 4.1.1

GDPR, Article 4 (11)

GDPR, Recital 32

GDPR, Article 6 (4)

GDPR, Article 83 (5) (a)


Contribute your Thoughts:

0/2000 characters
Valda
4 days ago
I think the company needs to obtain specific consent for the new processing. That seems to be the safest option.
upvoted 0 times
...

Save Cancel