What are the obligations of a processor that engages a sub-processor?
What are the obligations of a processor that engages a sub-processor? A. The processor must give the controller prior written notice and perform a preliminary audit of the sub- processor. B. The processor must obtain the controller’s specific written authorization and provide annual reports on the sub-processor’s performance. C. The...
How does the GDPR now define “processing”?
How does the GDPR now define “processing”?A . Any act involving the collecting and recording of personal data.B . Any operation or set of operations performed on personal data or on sets of personal data.C . Any use or disclosure of personal data compatible with the purpose for which the...
Which change was introduced by the 2009 amendments to the e-Privacy Directive 2002/58/EC?
Which change was introduced by the 2009 amendments to the e-Privacy Directive 2002/58/EC?A . A voluntary notification for personal data breaches applicable to all data controllers.B . A voluntary notification for personal data breaches applicable to electronic communication providers.C . A mandatory notification for personal data breaches applicable to all...
What is one potential problem Vigotron’s age policy might encounter under the GDPR?
Limitation of liability. […] Consent By completing this registration form, you attest that you are at least 16 years of age, and that you consent to the processing of your personal data by Vigotron for the purpose of using the M-Health app. Although you are entitled to opt out of...
Prior to doing so, the entity is required to provide users with notices containing information and consent under which of the following frameworks?
An entity’s website stores text files on EU users’ computer and mobile device browsers. Prior to doing so, the entity is required to provide users with notices containing information and consent under which of the following frameworks?A . General Data Protection Regulation 2016/679.B . E-Privacy Directive 2002/58/EC.C . E-Commerce Directive...
It a company receives an anonymous email demanding ransom for the stolen personal data of its clients, what must the company do next, per GDPR requirements'3
It a company receives an anonymous email demanding ransom for the stolen personal data of its clients, what must the company do next, per GDPR requirements'3A . Notify the police and Tile a criminal complaint about the incidentB . Start an investigation to understand the incident's possible scope, duration and...
If Who-R-U decides to track locations using its app, what must it do to comply with the GDPR?
SCENARIO Please use the following to answer the next question: Joe is the new privacy manager for Who-R-U, a Canadian business that provides DNA analysis. The company is headquartered in Montreal, and all of its employees are located there. The company offers its services to Canadians only: Its website is...
What is the consequence if a processor makes an independent decision regarding the purposes and means of processing it carries out on behalf of a controller?
What is the consequence if a processor makes an independent decision regarding the purposes and means of processing it carries out on behalf of a controller?A . The controller will be liable to pay an administrative fineB . The processor will be liable to pay compensation to affected data subjectsC...
Which statement is correct when considering the right to privacy under Article 8 of the European Convention on Human Rights (ECHR)?
Which statement is correct when considering the right to privacy under Article 8 of the European Convention on Human Rights (ECHR)?A . The right to privacy is an absolute rightB . The right to privacy has to be balanced against other rights under the ECHRC . The right to freedom...
What is true if an employee makes an access request to his employer for any personal data held about him?
What is true if an employee makes an access request to his employer for any personal data held about him?A . The employer can automatically decline the request if it contains personal data about a third person.B . The employer can decline the request if the information is only held...