If TripBliss Inc. decides not to report the incident to the supervisory authority, what would be their BEST defense?

SCENARIO Please use the following to answer the next question: TripBliss Inc. is a travel service company which has lost substantial revenue over the last few years. Their new manager, Oliver, suspects that this is partly due to the company’s outdated website. After doing some research, he meets with a...

January 3, 2021 2 Comments READ MORE +

Before Anna determines whether Frank’s performance database is permissible, what additional information does she need?

SCENARIO Please use the following to answer the next question: Anna and Frank both work at Granchester University. Anna is a lawyer responsible for data protection, while Frank is a lecturer in the engineering department. The University maintains a number of types of records: - Student records, including names, student...

January 3, 2021 No Comments READ MORE +

Which aspect of the GDPR will likely have the most impact on the consistent implementation of data protection laws throughout the European Union?

Which aspect of the GDPR will likely have the most impact on the consistent implementation of data protection laws throughout the European Union?A . That it essentially functions as a one-stop shop mechanismB . That it takes the form of a Regulation as opposed to a DirectiveC . That it...

January 2, 2021 2 Comments READ MORE +

Which institution has the power to adopt findings that confirm the adequacy of the data protection level in a non-EU country?

Which institution has the power to adopt findings that confirm the adequacy of the data protection level in a non-EU country?A . The European ParliamentB . The European CommissionC . The Article 29 Working PartyD . The European CouncilView AnswerAnswer: B Explanation: Reference: https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection/adequacy-decisions_en

January 2, 2021 No Comments READ MORE +

What is one major goal that the OECD Guidelines, Convention 108 and the Data Protection Directive (Directive 95/46/EC) all had in common but largely failed to achieve in Europe?

What is one major goal that the OECD Guidelines, Convention 108 and the Data Protection Directive (Directive 95/46/EC) all had in common but largely failed to achieve in Europe?A . The establishment of a list of legitimate data processing criteriaB . The creation of legally binding data protection principlesC ....

January 1, 2021 1 Comment READ MORE +

What type of data lies beyond the scope of the General Data Protection Regulation?

What type of data lies beyond the scope of the General Data Protection Regulation?A . PseudonymizedB . AnonymizedC . EncryptedD . MaskedView AnswerAnswer: B Explanation: Reference: https://www.datainspektionen.se/other-lang/in-english/the-general-data-protection-regulation-gdpr/the-purposes-and-scope-of-the-general-data-protection-regulation/

January 1, 2021 No Comments READ MORE +

What is the consequence if a processor makes an independent decision regarding the purposes and means of processing it carries out on behalf of a controller?

What is the consequence if a processor makes an independent decision regarding the purposes and means of processing it carries out on behalf of a controller?A . The controller will be liable to pay an administrative fineB . The processor will be liable to pay compensation to affected data subjectsC...

December 31, 2020 2 Comments READ MORE +

When collecting personal data in a European Union (EU) member state, what must a company do if it collects personal data from a source other than the data subjects themselves?

When collecting personal data in a European Union (EU) member state, what must a company do if it collects personal data from a source other than the data subjects themselves?A . Inform the subjects about the collectionB . Provide a public notice regarding the dataC . Upgrade security to match...

December 31, 2020 No Comments READ MORE +

How is the retention of communications traffic data for law enforcement purposes addressed by European data protection law?

How is the retention of communications traffic data for law enforcement purposes addressed by European data protection law?A . The ePrivacy Directive allows individual EU member states to engage in such data retention.B . The ePrivacy Directive harmonizes EU member states’ rules concerning such data retention.C . The Data Retention...

December 31, 2020 No Comments READ MORE +

When hiring a data processor, which action would a data controller NOT be able to depend upon to avoid liability in the event of a security breach?

When hiring a data processor, which action would a data controller NOT be able to depend upon to avoid liability in the event of a security breach?A . Documenting due diligence steps taken in the pre-contractual stage.B . Conducting a risk assessment to analyze possible outsourcing threats.C . Requiring that...

December 30, 2020 3 Comments READ MORE +