<< Prev Question Next Question >>

Question 47/72

SCENARIO
Please use the following to answer the next question:
Brady is a computer programmer based in New Zealand who has been running his own business for two years. Brady's business provides a low-cost suite of services to customers throughout the European Economic Area (EEA). The services are targeted towards new and aspiring small business owners. Brady's company, called Brady Box, provides web page design services, a Social Networking Service (SNS) and consulting services that help people manage their own online stores.
Unfortunately, Brady has been receiving some complaints. A customer named Anna recently uploaded her plans for a new product onto Brady Box's chat area, which is open to public viewing. Although she realized her mistake two weeks later and removed the document, Anna is holding Brady Box responsible for not noticing the error through regular monitoring of the website. Brady believes he should not be held liable.
Another customer, Felipe, was alarmed to discover that his personal information was transferred to a third- party contractor called Hermes Designs and worries that sensitive information regarding his business plans may be misused. Brady does not believe he violated European privacy rules. He provides a privacy notice to all of his customers explicitly stating that personal data may be transferred to specific third parties in fulfillment of a requested service. Felipe says he read the privacy notice but that it was long and complicated Brady continues to insist that Felipe has no need to be concerned, as he can personally vouch for the integrity of Hermes Designs. In fact, Hermes Designs has taken the initiative to create sample customized banner advertisements for customers like Felipe. Brady is happy to provide a link to the example banner ads, now posted on the Hermes Designs webpage. Hermes Designs plans on following up with direct marketing to these customers.
Brady was surprised when another customer, Serge, expressed his dismay that a quotation by him is being used within a graphic collage on Brady Box's home webpage. The quotation is attributed to Serge by first and last name. Brady, however, was not worried about any sort of litigation. He wrote back to Serge to let him know that he found the quotation within Brady Box's Social Networking Service (SNS), as Serge himself had posted the quotation. In his response, Brady did offer to remove the quotation as a courtesy.
Despite some customer complaints, Brady's business is flourishing. He even supplements his income through online behavioral advertising (OBA) via a third-party ad network with whom he has set clearly defined roles. Brady is pleased that, although some customers are not explicitly aware of the OBA, the advertisements contain useful products and services.
Based on current trends in European privacy practices, which aspect of Brady Box' Online Behavioral Advertising (OBA) is most likely to be insufficient if the company becomes established in Europe?

LEAVE A REPLY

Your email address will not be published. Required fields are marked *

Question List (72q)
Question 1: Which statement is correct when considering the right to pri...
Question 2: SCENARIO Please use the following to answer the next questio...
Question 3: SCENARIO Please use the following to answer the next questio...
Question 4: SCENARIO Please use the following to answer the next questio...
2 commentQuestion 5: Assuming that the "without undue delay" provision is followe...
Question 6: SCENARIO Please use the following to answer the next questio...
1 commentQuestion 7: SCENARIO Please use the following to answer the next questio...
Question 8: SCENARIO Please use the following to answer the next questio...
Question 9: Under what circumstances would the GDPR apply to personal da...
Question 10: SCENARIO Please use the following to answer the next questio...
Question 11: Which mechanism, new to the GDPR, now allows for the possibi...
Question 12: The Planet 49 CJEU Judgement applies to?...
Question 13: Which judicial body makes decisions on actions taken by indi...
Question 14: Which of the following is NOT an explicit right granted to d...
Question 15: The GDPR requires controllers to supply data subjects with d...
Question 16: SCENARIO Please use the following to answer the next questio...
Question 17: Many businesses print their employees' photographs on buildi...
Question 18: A company in France suffers a robbery over the weekend owing...
Question 19: Under Article 80(1) of the GDPR, individuals can elect to be...
Question 20: SCENARIO Please use the following to answer the next questio...
Question 21: Under what circumstances might the "soft opt-in" rule apply ...
Question 22: Which of the following is one of the supervisory authority's...
Question 23: SCENARIO Please use the following to answer the next questio...
1 commentQuestion 24: SCENARIO Please use the following to answer the next questio...
1 commentQuestion 25: A Spanish electricity customer calls her local supplier with...
Question 26: SCENARIO Please use the following to answer the next questio...
1 commentQuestion 27: Which of the following Convention 108+ principles, as amende...
Question 28: SCENARIO Please use the following to answer the next questio...
Question 29: Which area of privacy is a lead supervisory authority's (LSA...
Question 30: When hiring a data processor, which action would a data cont...
1 commentQuestion 31: SCENARIO Please use the following to answer the next questio...
Question 32: SCENARIO Please use the following to answer the next questio...
Question 33: SCENARIO Please use the following to answer the next questio...
Question 34: Which of the following is NOT a role of works councils?...
Question 35: Which institution has the power to adopt findings that confi...
Question 36: A U.S.-based online shop uses sophisticated software to trac...
Question 37: SCENARIO Please use the following to answer the next questio...
Question 38: What is the MAIN reason GDPR Article 4(22) establishes the c...
Question 39: In which of the following cases, cited as an example by a WP...
Question 40: SCENARIO Please use the following to answer the next questio...
Question 41: Company X has entrusted the processing of their payroll data...
Question 42: As per the GDPR, which legal basis would be the most appropr...
1 commentQuestion 43: SCENARIO Please use the following to answer the next questio...
Question 44: SCENARIO Please use the following to answer the next questio...
1 commentQuestion 45: An online company's privacy practices vary due to the fact t...
Question 46: A key component of the OECD Guidelines is the "Individual Pa...
Question 47: SCENARIO Please use the following to answer the next questio...
Question 48: SCENARIO Please use the following to answer the next questio...
Question 49: SCENARIO Please use the following to answer the next questio...
Question 50: SCENARIO Please use the following to answer the next questio...
Question 51: SCENARIO Please use the following to answer the next questio...
Question 52: A data controller appoints a data protection officer. Which ...
Question 53: Article 29 Working Party has emphasized that the GDPR forbid...
Question 54: WP29's "Guidelines on Personal data breach notification unde...
Question 55: Which of the following was the first legally binding interna...
Question 56: SCENARIO Please use the following to answer the next questio...
Question 57: According to the GDPR, when should the processing of photogr...
Question 58: SCENARIO Please use the following to answer the next questio...
Question 59: There are three domains of security covered by Article 32 of...
Question 60: What term BEST describes the European model for data protect...
Question 61: When does the GDPR provide more latitude for a company to pr...
Question 62: Article 9 of the GDPR lists exceptions to the general prohib...
Question 63: A U.S. company's website sells widgets. Which of the followi...
Question 64: A worker in a European Union (EU) member state has ceased hi...
Question 65: What must a data controller do in order to make personal dat...
Question 66: To which of the following parties does the territorial scope...
Question 67: Which of the following is the weakest lawful basis for proce...
Question 68: Which change was introduced by the 2009 amendments to the e-...
Question 69: What is true if an employee makes an access request to his e...
1 commentQuestion 70: Which aspect of the GDPR will likely have the most impact on...
Question 71: Which marketing-related activity is least likely to be cover...
Question 72: When would a data subject NOT be able to exercise the right ...