<< Prev Question Next Question >>

Question 4/81

SCENARIO
Please use the following to answer the next question:
Anna and Frank both work at Granchester University. Anna is a lawyer responsible for data protection, while Frank is a lecturer in the engineering department. The University maintains a number of types of records:
Student records, including names, student numbers, home addresses, pre-university information, university attendance and performance records, details of special educational needs and financial information.
Staff records, including autobiographical materials (such as curricula, professional contact files, student evaluations and other relevant teaching files).
Alumni records, including birthplaces, years of birth, dates of matriculation and conferrals of degrees. These records are available to former students after registering through Granchester's Alumni portal. Department for Education records, showing how certain demographic groups (such as first-generation students) could be expected, on average, to progress. These records do not contain names or identification numbers.
Under their security policy, the University encrypts all of its personal data records in transit and at rest.
In order to improve his teaching, Frank wants to investigate how his engineering students perform in relational to Department for Education expectations. He has attended one of Anna's data protection training courses and knows that he should use no more personal data than necessary to accomplish his goal. He creates a program that will only export some student data: previous schools attended, grades originally obtained, grades currently obtained and first time university attended. He wants to keep the records at the individual student level. Mindful of Anna's training, Frank runs the student numbers through an algorithm to transform them into different reference numbers. He uses the same algorithm on each occasion so that he can update each record over time.
One of Anna's tasks is to complete the record of processing activities, as required by the GDPR. After receiving her email reminder, as required by the GDPR. After receiving her email reminder, Frank informs Anna about his performance database.
Ann explains to Frank that, as well as minimizing personal data, the University has to check that this new use of existing data is permissible. She also suspects that, under the GDPR, a risk analysis may have to be carried out before the data processing can take place. Anna arranges to discuss this further with Frank after she has done some additional research.
Frank wants to be able to work on his analysis in his spare time, so he transfers it to his home laptop (which is not encrypted). Unfortunately, when Frank takes the laptop into the University he loses it on the train. Frank has to see Anna that day to discuss compatible processing. He knows that he needs to report security incidents, so he decides to tell Anna about his lost laptop at the same time.
Before Anna determines whether Frank's performance database is permissible, what additional information does she need?

LEAVE A REPLY

Your email address will not be published. Required fields are marked *

Question List (81q)
Question 1: To receive a preliminary interpretation on provisions of the...
Question 2: Please use the following to answer the next question: Joe st...
Question 3: The GDPR forbids the practice of "forum shopping", which occ...
Question 4: SCENARIO Please use the following to answer the next questio...
Question 5: A multinational company is appointing a mandatory data prote...
Question 6: When is data sharing agreement MOST likely to be needed?...
Question 7: SCENARIO Please use the following to answer the next questio...
Question 8: When may browser settings be relied upon for the lawful appl...
Question 9: Which of the following countries will continue to enjoy adeq...
Question 10: Please use the following to answer the next question: Due to...
Question 11: Article 58 of the GDPR describes the power of supervisory au...
Question 12: SCENARIO Please use the following to answer the next questio...
Question 13: When does the European Data Protection Board (EDPB) recommen...
Question 14: In which of the following cases, cited as an example by a WP...
Question 15: What should a controller do after a data subject opts out of...
Question 16: Which institution has the power to adopt findings that confi...
Question 17: SCENARIO Please use the following to answer the next questio...
Question 18: If a company is planning to use closed-circuit television (C...
Question 19: After leaving the EU under the terms of Brexit, the United K...
Question 20: Under what circumstances would the GDPR apply to personal da...
Question 21: SCENARIO Please use the following to answer the next questio...
Question 22: A mobile device application that uses cookies will be subjec...
Question 23: Which of the following describes a mandatory requirement for...
Question 24: SCENARIO Please use the following to answer the next questio...
Question 25: In which of the following cases would an organization MOST L...
Question 26: Bioface is a company based in the United States. It has no s...
Question 27: SCENARIO Please use the following to answer the next questio...
Question 28: How is the retention of communications traffic data for law ...
Question 29: Please use the following to answer the next question: Due to...
Question 30: SCENARIO Please use the following to answer the next questio...
Question 31: SCENARIO Please use the following to answer the next questio...
Question 32: Company X has entrusted the processing of their payroll data...
Question 33: Which of the following is NOT recognized as being a common c...
Question 34: A worker in a European Union (EU) member state has ceased hi...
Question 35: SCENARIO Please use the following to answer the next questio...
Question 36: Under what circumstances might the "soft opt-in" rule apply ...
Question 37: Which of the following demonstrates compliance with the acco...
Question 38: SCENARIO Please use the following to answer the next questio...
Question 39: What is the most frequently used mechanism for legitimizing ...
Question 40: A key component of the OECD Guidelines is the "Individual Pa...
Question 41: What is the MAIN reason GDPR Article 4(22) establishes the c...
Question 42: If a company chooses to ground an international data transfe...
Question 43: SCENARIO Please use the following to answer the next questio...
Question 44: What is the key difference between the European Council and ...
Question 45: SCENARIO Please use the following to answer the next questio...
Question 46: Based on GDPR Article 35, which of the following situations ...
Question 47: A Spanish electricity customer calls her local supplier with...
Question 48: SCENARIO Please use the following to answer the next questio...
Question 49: In which situation would a data controller most likely be ab...
Question 50: Tanya is the Data Protection Officer for Curtains Inc., a GD...
Question 51: Under the GDPR, which essential pieces of information must b...
Question 52: SCENARIO Please use the following to answer the next questio...
Question 53: As a result of the European Court of Justice's ruling in the...
Question 54: Read the following steps: Discover which employees are acces...
Question 55: SCENARIO Please use the following to answer the next questio...
Question 56: Which GDPR requirement will present the most significant cha...
Question 57: A U.S.-based online shop uses sophisticated software to trac...
Question 58: SCENARIO Please use the following to answer the next questio...
Question 59: What must a data controller do in order to make personal dat...
Question 60: What are the obligations of a processor that engages a sub-p...
Question 61: An employee of company ABCD has just noticed a memory stick ...
Question 62: Under the GDPR, which essential pieces of information must b...
Question 63: SCENARIO Please use the following to answer the next questio...
Question 64: SCENARIO Please use the following to answer the next questio...
Question 65: An organization conducts body temperature checks as a part o...
Question 66: According to the GDPR, when should the processing of photogr...
Question 67: An online company's privacy practices vary due to the fact t...
Question 68: What is a reason the European Court of Justice declared the ...
Question 69: Which change was introduced by the 2009 amendments to the e-...
Question 70: Under Article 30 of the GDPR, controllers are required to ke...
Question 71: As per the GDPR, which legal basis would be the most appropr...
Question 72: SCENARIO Please use the following to answer the next questio...
Question 73: SCENARIO Please use the following to answer the next questio...
Question 74: Under the Data Protection Law Enforcement Directive of the E...
Question 75: With the issue of consent, the GDPR allows member states som...
Question 76: When hiring a data processor, which action would a data cont...
Question 77: An organisation receives a request multiple times from a dat...
Question 78: Which of the following is NOT an explicit right granted to d...
Question 79: According to Article 84 of the GDPR, the rules on penalties ...
Question 80: An unforeseen power outage results in company Z's lack of ac...
Question 81: Under Article 80(1) of the GDPR, individuals can elect to be...