<< Prev Question Next Question >>

Question 72/81

SCENARIO
Please use the following to answer the next question:
Joe is the new privacy manager for Who-R-U, a Canadian business that provides DNA analysis. The company is headquartered in Montreal, and all of its employees are located there. The company offers its services to Canadians only: Its website is in English and French, it accepts only Canadian currency, and it blocks internet traffic from outside of Canada (although this solution doesn't prevent all non-Canadian traffic). It also declines to process orders that request the DNA report to be sent outside of Canada, and returns orders that show a non-Canadian return address.
Bob, the President of Who-R-U, thinks there is a lot of interest for the product in the EU, and the company is exploring a number of plans to expand its customer base.
The first plan, collegially called We-Track-U, will use an app to collect information about its current Canadian customer base. The expansion will allow its Canadian customers to use the app while traveling abroad. He suggests that the company use this app to gather location information. If the plan shows promise, Bob proposes to use push notifications and text messages to encourage existing customers to pre-register for an EU version of the service. Bob calls this work plan, We-Text-U. Once the company has gathered enough pre- registrations, it will develop EU-specific content and services.
Another plan is called Customer for Life. The idea is to offer additional services through the company's app, like storage and sharing of DNA information with other applications and medical providers. The company's contract says that it can keep customer DNA indefinitely, and use it to offer new services and market them to customers. It also says that customers agree not to withdraw direct marketing consent. Paul, the marketing director, suggests that the company should fully exploit these provisions, and that it can work around customers' attempts to withdraw consent because the contract invalidates them.
The final plan is to develop a brand presence in the EU. The company has already begun this process. It is in the process of purchasing the naming rights for a building in Germany, which would come with a few offices that Who-R-U executives can use while traveling internationally. The office doesn't include any technology or infrastructure; rather, it's simply a room with a desk and some chairs.
On a recent trip concerning the naming-rights deal, Bob's laptop is stolen. The laptop held unencrypted DNA reports on 5,000 Who-R-U customers, all of whom are residents of Canad a. The reports include customer name, birthdate, ethnicity, racial background, names of relatives, gender, and occasionally health information.
If Who-R-U adopts the We-Track-U pilot plan, why is it likely to be subject to the territorial scope of the GDPR?

LEAVE A REPLY

Your email address will not be published. Required fields are marked *

Question List (81q)
Question 1: To receive a preliminary interpretation on provisions of the...
Question 2: Please use the following to answer the next question: Joe st...
Question 3: The GDPR forbids the practice of "forum shopping", which occ...
Question 4: SCENARIO Please use the following to answer the next questio...
Question 5: A multinational company is appointing a mandatory data prote...
Question 6: When is data sharing agreement MOST likely to be needed?...
Question 7: SCENARIO Please use the following to answer the next questio...
Question 8: When may browser settings be relied upon for the lawful appl...
Question 9: Which of the following countries will continue to enjoy adeq...
Question 10: Please use the following to answer the next question: Due to...
Question 11: Article 58 of the GDPR describes the power of supervisory au...
Question 12: SCENARIO Please use the following to answer the next questio...
Question 13: When does the European Data Protection Board (EDPB) recommen...
Question 14: In which of the following cases, cited as an example by a WP...
Question 15: What should a controller do after a data subject opts out of...
Question 16: Which institution has the power to adopt findings that confi...
Question 17: SCENARIO Please use the following to answer the next questio...
Question 18: If a company is planning to use closed-circuit television (C...
Question 19: After leaving the EU under the terms of Brexit, the United K...
Question 20: Under what circumstances would the GDPR apply to personal da...
Question 21: SCENARIO Please use the following to answer the next questio...
Question 22: A mobile device application that uses cookies will be subjec...
Question 23: Which of the following describes a mandatory requirement for...
Question 24: SCENARIO Please use the following to answer the next questio...
Question 25: In which of the following cases would an organization MOST L...
Question 26: Bioface is a company based in the United States. It has no s...
Question 27: SCENARIO Please use the following to answer the next questio...
Question 28: How is the retention of communications traffic data for law ...
Question 29: Please use the following to answer the next question: Due to...
Question 30: SCENARIO Please use the following to answer the next questio...
Question 31: SCENARIO Please use the following to answer the next questio...
Question 32: Company X has entrusted the processing of their payroll data...
Question 33: Which of the following is NOT recognized as being a common c...
Question 34: A worker in a European Union (EU) member state has ceased hi...
Question 35: SCENARIO Please use the following to answer the next questio...
Question 36: Under what circumstances might the "soft opt-in" rule apply ...
Question 37: Which of the following demonstrates compliance with the acco...
Question 38: SCENARIO Please use the following to answer the next questio...
Question 39: What is the most frequently used mechanism for legitimizing ...
Question 40: A key component of the OECD Guidelines is the "Individual Pa...
Question 41: What is the MAIN reason GDPR Article 4(22) establishes the c...
Question 42: If a company chooses to ground an international data transfe...
Question 43: SCENARIO Please use the following to answer the next questio...
Question 44: What is the key difference between the European Council and ...
Question 45: SCENARIO Please use the following to answer the next questio...
Question 46: Based on GDPR Article 35, which of the following situations ...
Question 47: A Spanish electricity customer calls her local supplier with...
Question 48: SCENARIO Please use the following to answer the next questio...
Question 49: In which situation would a data controller most likely be ab...
Question 50: Tanya is the Data Protection Officer for Curtains Inc., a GD...
Question 51: Under the GDPR, which essential pieces of information must b...
Question 52: SCENARIO Please use the following to answer the next questio...
Question 53: As a result of the European Court of Justice's ruling in the...
Question 54: Read the following steps: Discover which employees are acces...
Question 55: SCENARIO Please use the following to answer the next questio...
Question 56: Which GDPR requirement will present the most significant cha...
Question 57: A U.S.-based online shop uses sophisticated software to trac...
Question 58: SCENARIO Please use the following to answer the next questio...
Question 59: What must a data controller do in order to make personal dat...
Question 60: What are the obligations of a processor that engages a sub-p...
Question 61: An employee of company ABCD has just noticed a memory stick ...
Question 62: Under the GDPR, which essential pieces of information must b...
Question 63: SCENARIO Please use the following to answer the next questio...
Question 64: SCENARIO Please use the following to answer the next questio...
Question 65: An organization conducts body temperature checks as a part o...
Question 66: According to the GDPR, when should the processing of photogr...
Question 67: An online company's privacy practices vary due to the fact t...
Question 68: What is a reason the European Court of Justice declared the ...
Question 69: Which change was introduced by the 2009 amendments to the e-...
Question 70: Under Article 30 of the GDPR, controllers are required to ke...
Question 71: As per the GDPR, which legal basis would be the most appropr...
Question 72: SCENARIO Please use the following to answer the next questio...
Question 73: SCENARIO Please use the following to answer the next questio...
Question 74: Under the Data Protection Law Enforcement Directive of the E...
Question 75: With the issue of consent, the GDPR allows member states som...
Question 76: When hiring a data processor, which action would a data cont...
Question 77: An organisation receives a request multiple times from a dat...
Question 78: Which of the following is NOT an explicit right granted to d...
Question 79: According to Article 84 of the GDPR, the rules on penalties ...
Question 80: An unforeseen power outage results in company Z's lack of ac...
Question 81: Under Article 80(1) of the GDPR, individuals can elect to be...