Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

IAPP CIPP-E Exam - Topic 5 Question 125 Discussion

SCENARIOPlease use the following to answer the next question:Dynaroux Fashion ('Dynaroux') is a successful international online clothing retailer that employs approximately 650 people at its headquarters based in Dublin, Ireland. Ronan is their recently appointed data protection officer, who oversees the company's compliance with the General Data Protection Regulation (GDPR) and other privacy legislation.The company offers both male and female clothing lines across all age demographics, including children. In doing so, the company processes large amounts of information about such customers, including preferences and sensitive financial information such as credit card and bank account numbers.In an aggressive bid to build revenue growth, Jonas, the CEO, tells Ronan that the company is launching a new mobile app and loyalty scheme that puts significant emphasis on profiling the company's customers by analyzing their purchases. Ronan tells the CEO that: (a) the potential risks of such activities means thatDynaroux needs to carry out a data protection impact assessment to assess this new venture and its privacy implications; and (b) where the results of this assessment indicate a high risk in the absence of appropriate protection measures, Dynaroux may have to undertake a prior consultation with the Irish Data Protection Commissioner before implementing the app and loyalty scheme.Jonas tells Ronan that he is not happy about the prospect of having to directly engage with a supervisory authority and having to disclose details of Dynaroux's business plan and associated processing activities.Which of the following facts about Dynaroux would trigger a data protection impact assessment under the GDPR?
C) The company plans to undertake profiling of its customers through analysis of their purchasing patterns.
A) The company will be undertaking processing activities involving sensitive data categories such as financial and children's data.
B) The company employs approximately 650 people and will therefore be carrying out extensive processing activities.
D) The company intends to shift their business model to rely more heavily on online shopping.

IAPP CIPP-E Exam - Topic 5 Question 125 Discussion

Actual exam question for IAPP's CIPP-E exam
Question #: 125
Topic #: 5
[All CIPP-E Questions]

SCENARIO

Please use the following to answer the next question:

Dynaroux Fashion ('Dynaroux') is a successful international online clothing retailer that employs approximately 650 people at its headquarters based in Dublin, Ireland. Ronan is their recently appointed data protection officer, who oversees the company's compliance with the General Data Protection Regulation (GDPR) and other privacy legislation.

The company offers both male and female clothing lines across all age demographics, including children. In doing so, the company processes large amounts of information about such customers, including preferences and sensitive financial information such as credit card and bank account numbers.

In an aggressive bid to build revenue growth, Jonas, the CEO, tells Ronan that the company is launching a new mobile app and loyalty scheme that puts significant emphasis on profiling the company's customers by analyzing their purchases. Ronan tells the CEO that: (a) the potential risks of such activities means that

Dynaroux needs to carry out a data protection impact assessment to assess this new venture and its privacy implications; and (b) where the results of this assessment indicate a high risk in the absence of appropriate protection measures, Dynaroux may have to undertake a prior consultation with the Irish Data Protection Commissioner before implementing the app and loyalty scheme.

Jonas tells Ronan that he is not happy about the prospect of having to directly engage with a supervisory authority and having to disclose details of Dynaroux's business plan and associated processing activities.

Which of the following facts about Dynaroux would trigger a data protection impact assessment under the GDPR?

Show Suggested Answer Hide Answer
Suggested Answer: C

According to theFree CIPP/E Study Guide, page 14, ''the GDPR requires controllers to carry out a data protection impact assessment (DPIA) prior to processing where a type of processing, in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons.'' The GDPR also provides a list of examples of processing operations that require a DPIA, such as ''a systematic and extensive evaluation of personal aspects relating to natural persons which is based on automated processing, including profiling, and on which decisions are based that produce legal effects concerning the natural person or similarly significantly affect the natural person'' (Article 35(3)(a)). Therefore, the fact that Dynaroux plans to undertake profiling of its customers through analysis of their purchasing patterns would trigger a DPIA under the GDPR, as it involves a systematic and extensive evaluation of personal aspects based on automated processing that may significantly affect the customers. The other options are not necessarily cases where a DPIA is required, although they may involve other obligations under the GDPR, such as obtaining a valid legal basis, providing adequate safeguards, or informing the data subjects.Reference:

Free CIPP/E Study Guide, page 14

GDPR, Article 35


Contribute your Thoughts:

0/2000 characters
Maryrose
1 day ago
B) Employee count alone isn’t enough to trigger a DPIA, right?
upvoted 0 times
...
Noemi
6 days ago
Wait, they’re profiling kids too? That sounds risky.
upvoted 0 times
...
Providencia
11 days ago
Totally agree, profiling customers is a big red flag!
upvoted 0 times
...
Ty
17 days ago
A) Sensitive data like financial info definitely needs a DPIA.
upvoted 0 times
...
Joaquin
22 days ago
Shifting to online shopping seems more like a business strategy than a data protection issue. I’m leaning towards options A and C being the main triggers.
upvoted 0 times
...
Fausto
27 days ago
I practiced a similar question where the focus was on the scale of data processing. I think option B might not be as strong a trigger as the others.
upvoted 0 times
...
Natalie
1 month ago
I’m not entirely sure, but I think profiling customers based on their purchases could also trigger a DPIA. It feels like it could lead to high risks.
upvoted 0 times
...
Jovita
1 month ago
I remember we discussed how sensitive data, especially related to children, is a major trigger for a DPIA under GDPR. So, option A seems really relevant.
upvoted 0 times
...

Save Cancel