<< Prev Question Next Question >>

Question 98/101

SCENARIO
Please use the following to answer the next question:
Joe started the Gummy Bear Company in 2000 from his home in Vermont, USA.
Today, it is a multi-billion-dollar candy company operating in every continent. All of the company's IT servers are located in Vermont. This year Joe hires his son Ben to join the company and head up Project Big, which is a major marketing strategy to triple gross revenue in just 5 years. Ben graduated with a PhD in computer software from a top university. Ben decided to join his father's company, but is also secretly working on launching a new global online dating website company called Ben Knows Best.
Ben is aware that the Gummy Bear Company has millions of customers and believes that many of them might also be interested in finding their perfect match. For Project Big, Ben redesigns the company's online web portal and requires customers in the European Union and elsewhere to provide additional personal information in order to remain a customer. Project Ben begins collecting data about customers' philosophical beliefs, political opinions and marital status.
If a customer identifies as single, Ben then copies all of that customer's personal data onto a separate database for Ben Knows Best. Ben believes that he is not doing anything wrong, because he explicitly asks each customer to give their consent by requiring them to check a box before accepting their information. As Project Big is an important project, the company also hires a first year college student named Sam, who is studying computer science to help Ben out.
Ben calls out and Sam comes across the Ben Knows Best database. Sam is planning on going to Ireland over Spring Beak with 10 of his friends, so he copies all of the customer information of people that reside in Ireland so that he and his friends can contact people when they are in Ireland.
Joe also hires his best friend's daughter, Alice, who just graduated from law school in the U.S., to be the company's new General Counsel. Alice has heard about the GDPR, so she does some research on it. Alice approaches Joe and informs him that she has drafted up Binding Corporate Rules for everyone in the company to follow, as it is important for the company to have in place a legal mechanism to transfer data internally from the company's operations in the European Union to the U.S.
Joe believes that Alice is doing a great job, and informs her that she will also be in-charge of handling a major lawsuit that has been brought against the company in federal court in the U.S. To prepare for the lawsuit, Alice instructs the company's IT department to make copies of the computer hard drives from the entire global sales team, including the European Union, and send everything to her so that she can review everyone's information. Alice believes that Joe will be happy that she did the first level review, as it will save the company a lot of money that would otherwise be paid to its outside law firm.
As a result of Sam's actions, the Gummy Bear Company potentially violated Articles 33 and 34 of the GDPR and will be required to do what?

LEAVE A REPLY

Your email address will not be published. Required fields are marked *

Question List (101q)
Question 1: SCENARIO Please use the following to answer the next questio...
Question 2: A well-known video production company, based in Spain but sp...
Question 3: SCENARIO Please use the following to answer the next questio...
Question 4: With the issue of consent, the GDPR allows member states som...
Question 5: If a company chooses to ground an international data transfe...
Question 6: What is the most frequently used mechanism for legitimizing ...
Question 7: WP29's "Guidelines on Personal data breach notification unde...
Question 8: What is the key difference between the European Council and ...
Question 9: SCENARIO Please use the following to answer the next questio...
Question 10: What is an important difference between the European Court o...
Question 11: SCENARIO Please use the following to answer the next questio...
Question 12: Which sentence BEST summarizes the concepts of "fairness," "...
1 commentQuestion 13: The GDPR specifies fines that may be levied against data con...
1 commentQuestion 14: SCENARIO Please use the following to answer the next questio...
Question 15: SCENARIO Please use the following to answer the next questio...
Question 16: What is true if an employee makes an access request to his e...
Question 17: An organisation receives a request multiple times from a dat...
Question 18: Read the following steps: Discover which employees are acces...
Question 19: To provide evidence of GDPR compliance, a company performs a...
Question 20: SCENARIO Please use the following to answer the next questio...
Question 21: A well-known video production company, based in Spain but sp...
Question 22: Which of the following would require designating a data prot...
Question 23: SCENARIO Please use the following to answer the next questio...
Question 24: Which statement is correct when considering the right to pri...
Question 25: SCENARIO Please use the following to answer the next questio...
1 commentQuestion 26: Under which of the following conditions does the General Dat...
Question 27: SCENARIO Please use the following to answer the next questio...
Question 28: A grade school is planning to use facial recognition to trac...
Question 29: Which of the following was the first legally binding interna...
Question 30: Under the GDPR, who would be LEAST likely to be allowed to e...
Question 31: Under Article 21 of the GDPR, a controller must stop profili...
Question 32: SCENARIO Please use the following to answer the next questio...
Question 33: A company in France suffers a robbery over the weekend owing...
Question 34: SCENARIO Please use the following to answer the next questio...
Question 35: In which situation would a data controller most likely be ab...
Question 36: In the event of a data breach, which type of information are...
1 commentQuestion 37: Which of the following would MOST likely trigger the extrate...
Question 38: According to the European Data Protection Board, which of th...
Question 40: Pursuant to Article 4(5) of the GDPR, data is considered "ps...
Question 41: An unforeseen power outage results in company Z's lack of ac...
Question 42: As per the GDPR, which legal basis would be the most appropr...
Question 43: What should a controller do after a data subject opts out of...
Question 44: SCENARIO Please use the following to answer the next questio...
Question 45: In addition to the European Commission, who can adopt standa...
Question 46: If a company is planning to use closed-circuit television (C...
Question 47: What is the MAIN reason GDPR Article 4(22) establishes the c...
Question 48: The GDPR forbids the practice of "forum shopping", which occ...
Question 49: To which of the following parties does the territorial scope...
Question 50: If a French controller has a car-sharing app available only ...
Question 51: Under what circumstances might the "soft opt-in" rule apply ...
Question 52: Which of the following would NOT be relevant when determinin...
Question 53: A German data subject was the victim of an embarrassing pran...
Question 54: An organization receives a request multiple times from a dat...
Question 55: If a data subject puts a complaint before a DPA and receives...
Question 56: Which of the following does NOT have to be included in the r...
Question 57: SCENARIO Please use the following to answer the next questio...
Question 58: SCENARIO Please use the following to answer the next questio...
Question 59: What obligation does a data controller or processor have aft...
Question 60: SCENARIO Please use the following to answer the next questio...
Question 61: SCENARIO Please use the following to answer the next Questio...
Question 62: As a result of the European Court of Justice's ruling in the...
Question 63: In which of the following cases would an organization MOST L...
Question 64: A worker in a European Union (EU) member state has ceased hi...
Question 65: Under what circumstances would the GDPR apply to personal da...
Question 66: Which of the following is NOT considered a fair processing p...
Question 67: What is the key difference between the European Council and ...
Question 68: Which of the following countries will continue to enjoy adeq...
Question 69: Which type of personal data does the GDPR define as a "speci...
Question 70: An organization conducts body temperature checks as a part o...
Question 71: What is true if an employee makes an access request to his e...
Question 72: SCENARIO Please use the following to answer the next questio...
Question 73: SCENARIO Please use the following to answer the next questio...
Question 74: SCENARIO Please use the following to answer the next questio...
Question 75: Under what circumstances might the "soft opt-in" rule apply ...
Question 76: What term BEST describes the European model for data protect...
Question 77: Which of the following is one of the supervisory authority's...
Question 78: Based on GDPR Article 35, which of the following situations ...
Question 79: SCENARIO Please use the following to answer the next questio...
Question 80: SCENARIO Please use the following to answer the next questio...
Question 81: Which judicial body makes decisions on actions taken by indi...
Question 82: What is one major goal that the OECD Guidelines, Convention ...
Question 83: Under which of the following conditions does the General Dat...
Question 84: Which GDPR principle would a Spanish employer most likely de...
Question 85: What permissions are required for a marketer to send an emai...
Question 86: According to the E-Commerce Directive 2000/31/EC, where is t...
Question 87: A company is hesitating between Binding Corporate Rules and ...
Question 88: In which of the following situations would an individual mos...
Question 89: Which change was introduced by the 2009 amendments to the e-...
Question 90: SCENARIO Please use the following to answer the next questio...
Question 91: Tanya is the Data Protection Officer for Curtains Inc., a GD...
Question 92: What must be included in a written agreement between the con...
Question 93: SCENARIO Please use the following to answer the next questio...
Question 94: SCENARIO Please use the following to answer the next questio...
Question 95: Which EU institution is vested with the competence to propos...
Question 96: Tanya is the Data Protection Officer for Curtains Inc., a GD...
Question 97: SCENARIO Please use the following to answer the next questio...
Question 98: SCENARIO Please use the following to answer the next questio...
Question 99: SCENARIO Please use the following to answer the next questio...
Question 100: Which of the following is NOT an explicit right granted to d...
Question 101: Under Article 21 of the GDPR, a controller must stop profili...