IAPP CIPP-E Exam - Topic 5 Question 25 Discussion
To provide evidence of GDPR compliance, a company performs an internal audit. As a result, it finds a data base, password-protected, listing all the social network followers of the client.Regarding the domain of the controller-processor relationships, how is this situation considered?
B) Non-compliant, because the storage of the data exceeds the tasks contractually authorized by the controller.
A) Compliant with the security principle, because the data base is password-protected.
C) Not applicable, because the data base is password protected, and therefore is not at risk of identifying any data subject.
D) Compliant with the storage limitation principle, so long as the internal auditor permanently deletes the data base.
Charlie
11 months agoCarylon
11 months agoPatti
11 months agoHolley
11 months agoDorthy
11 months agoPauline
11 months agoStevie
11 months agoAgustin
11 months agoEssie
11 months agoSuzi
12 months agoLizette
12 months agoLuz
12 months agoDorathy
12 months ago