WP29's ''Guidelines on Personal data breach notification under Regulation 2016/679'' provides examples of ways to communicate data breaches transparently. Which of the following was listed as a method that would NOT be effective for communicating a breach to data subjects?
According to the WP29's ''Guidelines on Personal data breach notification under Regulation 2016/679'', the communication of a personal data breach to the data subjects should be clear, concise, transparent, easily accessible and understandable, and use clear and plain language. The communication should also be made as soon as reasonably feasible and in close cooperation with the supervisory authority. The guidelines provide some examples of methods that may be effective for communicating a breach to data subjects, such as a direct electronic message (e.g. email, SMS, direct message), a postal notification, a prominent advertisement in print media, or a notice on the homepage of the affected website. However, the guidelines also state that a notice on a corporate blog or social media would not be an effective method of communication, as it would not reach all the affected data subjects and would not allow them to take immediate action to protect themselves. Therefore, the correct answer is C. A notice on a corporate blog.Reference:
WP29's ''Guidelines on Personal data breach notification under Regulation 2016/679'', pages 20-211
SCENARIO
Please use the following to answer the next question:
Dynaroux Fashion ('Dynaroux') is a successful international online clothing retailer that employs approximately 650 people at its headquarters based in Dublin, Ireland. Ronan is their recently appointed data protection officer, who oversees the company's compliance with the General Data Protection Regulation (GDPR) and other privacy legislation.
The company offers both male and female clothing lines across all age demographics, including children. In doing so, the company processes large amounts of information about such customers, including preferences and sensitive financial information such as credit card and bank account numbers.
In an aggressive bid to build revenue growth, Jonas, the CEO, tells Ronan that the company is launching a new mobile app and loyalty scheme that puts significant emphasis on profiling the company's customers by analyzing their purchases. Ronan tells the CEO that: (a) the potential risks of such activities means that
Dynaroux needs to carry out a data protection impact assessment to assess this new venture and its privacy implications; and (b) where the results of this assessment indicate a high risk in the absence of appropriate protection measures, Dynaroux may have to undertake a prior consultation with the Irish Data Protection Commissioner before implementing the app and loyalty scheme.
Jonas tells Ronan that he is not happy about the prospect of having to directly engage with a supervisory authority and having to disclose details of Dynaroux's business plan and associated processing activities.
Which of the following facts about Dynaroux would trigger a data protection impact assessment under the GDPR?
According to theFree CIPP/E Study Guide, page 14, ''the GDPR requires controllers to carry out a data protection impact assessment (DPIA) prior to processing where a type of processing, in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons.'' The GDPR also provides a list of examples of processing operations that require a DPIA, such as ''a systematic and extensive evaluation of personal aspects relating to natural persons which is based on automated processing, including profiling, and on which decisions are based that produce legal effects concerning the natural person or similarly significantly affect the natural person'' (Article 35(3)(a)). Therefore, the fact that Dynaroux plans to undertake profiling of its customers through analysis of their purchasing patterns would trigger a DPIA under the GDPR, as it involves a systematic and extensive evaluation of personal aspects based on automated processing that may significantly affect the customers. The other options are not necessarily cases where a DPIA is required, although they may involve other obligations under the GDPR, such as obtaining a valid legal basis, providing adequate safeguards, or informing the data subjects.Reference:
Free CIPP/E Study Guide, page 14
GDPR, Article 35
Once an organization has conducted an internal investigation to determine the scope of a ransomware attack, what is the appropriate next step in the process?
The GDPR (General Data Protection Regulation) has strict data breach response requirements, particularly for ransomware attacks that affect personal data. The appropriate next step after an internal investigation is to assess the risks associated with the breach and notify affected parties if necessary.
Key GDPR Breach Response Steps (Article 33 & 34):
Assess the risks to personal data
If the breach poses a risk to individuals' rights and freedoms, the supervisory authority (DPA) must be notified within 72 hours.
If there is a high risk, affected individuals must also be informed without undue delay.
Why Answer Choice A is Correct
Risk assessment is a critical first step after an internal investigation.
If the breach meets the risk threshold, notification to authorities and individuals is required under GDPR.
Why Other Answer Choices Are Incorrect:
B (Notify Law Enforcement First): While law enforcement may be involved, GDPR does not mandate consulting law enforcement before conducting a risk assessment or notifying individuals.
C (Informing the Public Immediately): Public disclosure via social media is not a GDPR requirement. Affected individuals and DPAs should be formally notified first.
D (Waiting for Law Enforcement): GDPR does not allow waiting for law enforcement before fulfilling notification obligations. Controllers must act within 72 hours.
Conclusion: The correct next step after an internal investigation is to assess the risks and, if necessary, notify affected individuals and regulatory bodies as required under GDPR Articles 33 and 34.
According to the E-Commerce Directive 2000/31/EC, where is the place of ''establishment'' for a company providing services via an Internet website confirmed by the GDPR?
According to the E-Commerce Directive 2000/31/EC, the place of establishment for a company providing services via an Internet website is the place where the service provider effectively pursues an economic activity through a fixed establishment for an indefinite period of time. The presence and use of the technical means and technologies required to provide the service do not, in themselves, constitute an establishment of the provider. The place of establishment is determined by the place where the decisions about processing are made, not by the place where the technology supporting the website is located, where the website is accessed, or where the customer's Internet service provider is located. This is confirmed by the GDPR, which applies to the processing of personal data in the context of the activities of an establishment of a controller or a processor in the EU, regardless of whether the processing takes place in the EU or not.Reference:
E-Commerce Directive 2000/31/EC, Article 2(a), Recital 191
GDPR, Article 3(1)2
Which of the following describes a mandatory requirement for a group of undertakings that wants to appoint a single data protection officer?
According to Article 37(2) of the GDPR, a group of undertakings may appoint a single data protection officer (DPO) provided that the DPO is easily accessible from each establishment12.This means that the DPO should be able to communicate effectively with the data subjects and the supervisory authorities in the relevant languages and jurisdictions, and to perform the tasks referred to in Article 39 of the GDPR34.The accessibility of the DPO does not necessarily depend on the physical location of the DPO, but rather on the availability of the DPO to the relevant stakeholders via various means of communication34. Therefore, the DPO does not have to be located in the country where the data controller has its main establishment, nor does the group of undertakings have to obtain approval from a supervisory authority or be comprised of organizations of similar sizes and functions to appoint a single DPO.Reference:CIPP/E Certification - International Association of Privacy Professionals,Free CIPP/E Study Guide - International Association of Privacy Professionals,GDPR - EUR-Lex,What's different about a group data protection officer?,Data Protection Officers: What US Companies Need to Know - Cooley
Carol Lopez
5 days agoThomas Smith
27 days agoSharon Rogers
1 month agoStephanie Collins
2 months agoPaul Bell
2 months agoDaniel Green
3 months agoNathan Turner
3 months agoSharon Baker
3 months agoSarah Wright
3 months agoRonald Moore
3 months agoSusan Johnson
3 months agoTimothy Walker
3 months agoGerman
4 months agoGeorgene
4 months agoLeonora
4 months agoXuan
5 months agoMaybelle
5 months agoChandra
5 months agoFrederic
5 months agoMarti
6 months agoBrandon
6 months agoDylan
6 months agoChaya
6 months agoRose
7 months agoValda
7 months agoMiesha
7 months agoTommy
7 months agoUla
8 months agoGary
8 months agoRoosevelt
8 months agoHyun
8 months agoRolf
9 months agoCyril
9 months agoBernardo
9 months agoAmmie
9 months agoAliza
10 months agoSylvia
10 months agoDarnell
10 months agoAdell
10 months agoYasuko
10 months agoRegenia
11 months agoBilly
11 months agoWhitney
11 months agoAvery
1 year agoIra
1 year agoJade
1 year agoDesiree
1 year agoVeda
1 year agoShawna
1 year agoLatrice
1 year agoKristian
1 year agoShawna
1 year agoTherese
1 year agoGwenn
1 year agoTerry
1 year agoRikki
2 years agoCatalina
2 years agoRemona
2 years agoGilberto
2 years agoTesha
2 years agoGolda
2 years agoCatarina
2 years agoRuthann
2 years agoLouisa
2 years agoEsteban
2 years agoAhmad
2 years agoFernanda
2 years agoClarence
2 years agoMerissa
2 years agoPhil
2 years agoLinsey
2 years agoAlida
2 years agoWillodean
2 years agoJosephine
2 years agoErinn
2 years agoVeronique
2 years agoWayne
2 years agoJill
2 years agoHector
2 years agoFlorencia
2 years agoRaelene
2 years agoJoesph
2 years agoFidelia
2 years agoHyun
2 years agoMireya
2 years ago