Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

IAPP CIPP/US Exam - Topic 3 Question 98 Discussion

SCENARIOPlease use the following to answer the next QUESTION:A US-based startup company is selling a new gaming application. One day, the CEO of the company receives an urgent letter from a prominent EU-based retail partner. Triggered by an unresolved complaint lodged by an EU resident, the letter describes an ongoing investigation by a supervisory authority into the retailer's data handling practices.The complainant accuses the retailer of improperly disclosing her personal data, without consent, to parties in the United States. Further, the complainant accuses the EU-based retailer of failing to respond to herwithdrawal of consent and request for erasure of her personal data. Your organization, the US-based startup company, was never informed of this request for erasure by the EU-based retail partner. The supervisory authority investigating the complaint has threatened the suspension of data flows if the parties involved do not cooperate with the investigation. The letter closes with an urgent request: ''Please act immediately by identifying all personal data received from our company.''This is an important partnership. Company executives know that its biggest fans come from Western Europe; and this retailer is primarily responsible for the startup's rapid market penetration.As the Company's data privacy leader, you are sensitive to the criticality of the relationship with the retailer.Under the General Data Protection Regulation (GDPR), how would the U.S.-based startup company most likely be classified?
B) As a data processor
A) As a data supervisor
C) As a data controller
D) As a data manager

IAPP CIPP/US Exam - Topic 3 Question 98 Discussion

Actual exam question for IAPP's CIPP/US exam
Question #: 98
Topic #: 3
[All CIPP/US Questions]

SCENARIO

Please use the following to answer the next QUESTION:

A US-based startup company is selling a new gaming application. One day, the CEO of the company receives an urgent letter from a prominent EU-based retail partner. Triggered by an unresolved complaint lodged by an EU resident, the letter describes an ongoing investigation by a supervisory authority into the retailer's data handling practices.

The complainant accuses the retailer of improperly disclosing her personal data, without consent, to parties in the United States. Further, the complainant accuses the EU-based retailer of failing to respond to her

withdrawal of consent and request for erasure of her personal dat

a. Your organization, the US-based startup company, was never informed of this request for erasure by the EU-based retail partner. The supervisory authority investigating the complaint has threatened the suspension of data flows if the parties involved do not cooperate with the investigation. The letter closes with an urgent request: ''Please act immediately by identifying all personal data received from our company.''

This is an important partnership. Company executives know that its biggest fans come from Western Europe; and this retailer is primarily responsible for the startup's rapid market penetration.

As the Company's data privacy leader, you are sensitive to the criticality of the relationship with the retailer.

Under the General Data Protection Regulation (GDPR), how would the U.S.-based startup company most likely be classified?

Show Suggested Answer Hide Answer
Suggested Answer: B

The data privacy leader needs to identify all the personal data that the Company has received from the retailer, as well as the purposes, retention periods, and sharing practices of such data. Since the data inventory is obsolete, the data privacy leader cannot rely on it to provide accurate and complete information. Therefore, the next best source of information is to interview the key marketing personnel who are responsible for the partnership with the retailer and the use of the personal data. The marketing personnel can provide insights into the data flows, the data categories, the data processing activities, and the data protection measures that the Company has implemented. They can also help the data privacy leader to locate the relevant documents, contracts, and records that can support the investigation.Reference:[IAPP CIPP/US Study Guide], Chapter 5: Data Management, p. 97-98;IAPP Privacy Tech Vendor Report, Data Mapping and Inventory, p. 9-10.


Contribute your Thoughts:

0/2000 characters
Novella
4 days ago
I’m confused about the terms. I thought data managers were more about organizing data, but this seems to be about legal responsibilities.
upvoted 0 times
...
Mila
9 days ago
This scenario feels similar to a practice question we did on GDPR classifications. I think the startup could be a data controller because they benefit from the data.
upvoted 0 times
...
Jaime
14 days ago
I’m not entirely sure, but I remember something about data controllers having more responsibility for data handling. Could that apply here?
upvoted 0 times
...
Dusti
20 days ago
I think the startup might be classified as a data processor since they’re handling data from the retailer but not making decisions about it.
upvoted 0 times
...

Save Cancel