If Who-R-U adopts the We-Track-U pilot plan, why is it likely to be subject to the territorial scope of the GDPR?

SCENARIO Please use the following to answer the next question: Joe is the new privacy manager for Who-R-U, a Canadian business that provides DNA analysis. The company is headquartered in Montreal, and all of its employees are located there. The company offers its services to Canadians only: Its website is...

January 20, 2024 No Comments READ MORE +

According to Article 14 of the GDPR, how long does a controller have to provide a data subject with necessary privacy information, if that subject’s personal data has been obtained from other sources?

According to Article 14 of the GDPR, how long does a controller have to provide a data subject with necessary privacy information, if that subject’s personal data has been obtained from other sources?A . As soon as possible after obtaining the personal data.B . As soon as possible after the...

January 19, 2024 No Comments READ MORE +

Which sentence best describes proper compliance for an international organization using Binding Corporate Rules (BCRs) as a controller or processor?

Which sentence best describes proper compliance for an international organization using Binding Corporate Rules (BCRs) as a controller or processor?A . Employees must sign an ad hoc contractual agreement each time personal data is exported.B . All employees are subject to the rules in their entirety, regardless of where the...

January 19, 2024 No Comments READ MORE +

What should the employer most likely do in regard to the worker’s personal data?

A worker in a European Union (EU) member state has ceased his employment with a company. What should the employer most likely do in regard to the worker’s personal data?A . Destroy sensitive information and store the rest per applicable data protection rules.B . Store all of the data in...

January 19, 2024 No Comments READ MORE +

The Planet 49 CJEU Judgement applies to?

The Planet 49 CJEU Judgement applies to?A . Cookies used only by third parties.B . Cookies that are deemed technically necessary.C . Cookies regardless of whether the data accessed is personal or not.D . Cookies where the data accessed is considered as personal data only.View AnswerAnswer: C Explanation: Reference: https://www.twobirds.com/en/news/articles/2019/global/planet49-cjeu-rules-on-cookie-consent

January 19, 2024 No Comments READ MORE +

Under which of the following conditions does the General Data Protection Regulation NOT apply to the processing of personal data?

Under which of the following conditions does the General Data Protection Regulation NOT apply to the processing of personal data? A. When the personal data is processed only in non-electronic form B. When the personal data is collected and then pseudonymised by the controller C. When the personal data is...

January 19, 2024 No Comments READ MORE +

What is the most realistic step the company could take to address their security concerns and comply with the personal data processing principles set out in Article 5 of the GDPR?

A company in France suffers a robbery over the weekend owing to a faulty alarm system. When it is determined that the break-in involves the loss of a substantial amount of data, the company decides on a CCTV system to monitor for future incidents. Company technicians install cameras in the...

January 19, 2024 No Comments READ MORE +

What is one potential problem Vigotron’s age policy might encounter under the GDPR?

Limitation of liability. […] Consent By completing this registration form, you attest that you are at least 16 years of age, and that you consent to the processing of your personal data by Vigotron for the purpose of using the M-Health app. Although you are entitled to opt out of...

January 19, 2024 No Comments READ MORE +

Which change was introduced by the 2009 amendments to the e-Privacy Directive 2002/58/EC?

Which change was introduced by the 2009 amendments to the e-Privacy Directive 2002/58/EC?A . A voluntary notification for personal data breaches applicable to all data controllers.B . A voluntary notification for personal data breaches applicable to electronic communication providers.C . A mandatory notification for personal data breaches applicable to all...

January 19, 2024 No Comments READ MORE +

Which of the following is NOT recognized as being a common characteristic of cloud-computing services?

Which of the following is NOT recognized as being a common characteristic of cloud-computing services?A . The service’s infrastructure is shared among the supplier’s customers and can be located in a number of countries.B . The supplier determines the location, security measures, and service standards applicable to the processing.C ....

January 19, 2024 No Comments READ MORE +