<< Prev Question Next Question >>

Question 142/166

SCENARIO
Please use the following to answer the next question:
Anna and Frank both work at Granchester University. Anna is a lawyer responsible for data protection, while Frank is a lecturer in the engineering department. The University maintains a number of types of records:
* Student records, including names, student numbers, home addresses, pre-university information, university attendance and performance records, details of special educational needs and financial information.
* Staff records, including autobiographical materials (such as curricula, professional contact files, student evaluations and other relevant teaching files).
* Alumni records, including birthplaces, years of birth, dates of matriculation and conferrals of degrees.
These records are available to former students after registering through Granchester's Alumni portal.
* Department for Education records, showing how certain demographic groups (such as first-generation students) could be expected, on average, to progress. These records do not contain names or identification numbers.
* Under their security policy, the University encrypts all of its personal data records in transit and at rest.
In order to improve his teaching, Frank wants to investigate how his engineering students perform in relational to Department for Education expectations. He has attended one of Anna's data protection training courses and knows that he should use no more personal data than necessary to accomplish his goal. He creates a program that will only export some student data: previous schools attended, grades originally obtained, grades currently obtained and first time university attended. He wants to keep the records at the individual student level. Mindful of Anna's training, Frank runs the student numbers through an algorithm to transform them into different reference numbers. He uses the same algorithm on each occasion so that he can update each record over time.
One of Anna's tasks is to complete the record of processing activities, as required by the GDPR. After receiving her email reminder, as required by the GDPR. After receiving her email reminder, Frank informs Anna about his performance database.
Ann explains to Frank that, as well as minimizing personal data, the University has to check that this new use of existing data is permissible. She also suspects that, under the GDPR, a risk analysis may have to be carried out before the data processing can take place. Anna arranges to discuss this further with Frank after she has done some additional research.
Frank wants to be able to work on his analysis in his spare time, so he transfers it to his home laptop (which is not encrypted). Unfortunately, when Frank takes the laptop into the University he loses it on the train. Frank has to see Anna that day to discuss compatible processing. He knows that he needs to report security incidents, so he decides to tell Anna about his lost laptop at the same time.
Anna will find that a risk analysis is NOT necessary in this situation as long as?

LEAVE A REPLY

Your email address will not be published. Required fields are marked *

Question List (166q)
Question 1: With the issue of consent, the GDPR allows member states som...
Question 2: What is true of both the General Data Protection Regulation ...
Question 3: What permissions are required for a marketer to send an emai...
Question 4: Which of the following is an accurate statement regarding th...
Question 5: How does the GDPR now define "processing"?...
Question 6: Which sentence best describes proper compliance for an inter...
Question 7: How is the retention of communications traffic data for law ...
Question 8: SCENARIO Please use the following to answer the next questio...
Question 9: The GDPR specifies fines that may be levied against data con...
Question 10: A U.S. company's website sells widgets. Which of the followi...
Question 11: SCENARIO Please use the following to answer the next questio...
Question 12: Higher fines are assessed for GDPR violations due to which o...
Question 13: For which of the following operations would an employer most...
Question 14: An employee of company ABCD has just noticed a memory stick ...
Question 15: What obligation does a data controller or processor have aft...
Question 16: SCENARIO Please use the following to answer the next questio...
Question 17: Under what circumstances would the GDPR apply to personal da...
Question 18: SCENARIO Please use the following to answer the next questio...
Question 19: SCENARIO Please use the following to answer the next questio...
Question 20: After leaving the EU under the terms of Brexit, the United K...
Question 21: SCENARIO Please use the following to answer the next questio...
Question 22: SCENARIO Please use the following to answer the next questio...
Question 23: SCENARIO Please use the following to answer the next questio...
Question 24: What is the consequence if a processor makes an independent ...
Question 25: Article 9 of the GDPR lists exceptions to the general prohib...
Question 26: Which area of privacy is a lead supervisory authority's (LSA...
Question 27: Which aspect of the GDPR will likely have the most impact on...
Question 28: A grade school is planning to use facial recognition to trac...
Question 29: Under the GDPR, which essential pieces of information must b...
Question 30: Under the GDPR, who would be LEAST likely to be allowed to e...
Question 31: Under the GDPR, who would be LEAST likely to be allowed to e...
Question 32: Under Article 21 of the GDPR, a controller must stop profili...
Question 33: SCENARIO Please use the following to answer the next questio...
Question 34: SCENARIO Please use the following to answer the next questio...
Question 35: An entity's website stores text files on EU users' computer ...
Question 36: Under Article 80(1) of the GDPR, individuals can elect to be...
Question 37: What term BEST describes the European model for data protect...
Question 38: SCENARIO Please use the following to answer the next questio...
Question 39: What is one major goal that the OECD Guidelines, Convention ...
Question 40: SCENARIO Please use the following to answer the next questio...
Question 41: What are the obligations of a processor that engages a sub-p...
Question 42: SCENARIO Please use the following to answer the next Questio...
Question 43: SCENARIO Please use the following to answer the next questio...
Question 44: In which scenario is a Controller most likely required to un...
Question 45: A U.S.-based online shop uses sophisticated software to trac...
Question 46: SCENARIO Please use the following to answer the next questio...
Question 47: SCENARIO Please use the following to answer the next questio...
Question 48: In relation to third countries and international organizatio...
Question 49: Please use the following to answer the next question: Jane S...
Question 50: When does the European Data Protection Board (EDPB) recommen...
Question 51: Why is advisable to avoid consent as a legal basis for an em...
Question 52: In 2016's Guidance, the United Kingdom's Information Commiss...
Question 53: Which of the following would require designating a data prot...
Question 54: According to the GDPR. Article 4(14). biometric data is defi...
Question 55: SCENARIO Please use the following to answer the next questio...
Question 56: SCENARIO Please use the following to answer the next questio...
Question 57: Company X has entrusted the processing of their payroll data...
Question 58: According to the GDPR, what is the main task of a Data Prote...
Question 59: Which type of personal data does the GDPR define as a "speci...
Question 60: SCENARIO Please use the following to answer the next questio...
Question 61: Under what circumstances would the GDPR apply to personal da...
Question 62: Select the answer below that accurately completes the follow...
Question 63: What term BEST describes the European model for data protect...
Question 64: Assuming that the "without undue delay" provision is followe...
Question 65: The GDPR forbids the practice of "forum shopping", which occ...
Question 66: WP29's "Guidelines on Personal data breach notification unde...
Question 67: Tanya is the Data Protection Officer for Curtains Inc., a GD...
Question 68: SCENARIO Please use the following to answer the next questio...
Question 69: Which of the following would MOST likely trigger the extrate...
Question 70: SCENARIO Please use the following to answer the next questio...
Question 71: What is the key difference between the European Council and ...
Question 72: According to Article 14 of the GDPR, how long does a control...
Question 73: Please use the following to answer the next question: Jane S...
Question 74: To which of the following parties does the territorial scope...
Question 75: What is an important difference between the European Court o...
Question 76: What are the obligations of a processor that engages a sub-p...
Question 77: SCENARIO Please use the following to answer the next questio...
Question 78: A well-known video production company, based in Spain but sp...
Question 79: SCENARIO Please use the following to answer the next questio...
Question 80: Assuming that the "without undue delay" provision is followe...
Question 81: The transparency principle is most directly related to which...
Question 82: The European Data Protection Board (EDPB) recommends measure...
Question 83: Based on GDPR Article 35, which of the following situations ...
Question 84: Which mechanism, new to the GDPR, now allows for the possibi...
Question 85: A well-known video production company, based in Spain but sp...
Question 86: SCENARIO Please use the following to answer the next questio...
Question 87: Which of the following would MOST likely trigger the extrate...
Question 88: What is one major goal that the OECD Guidelines, Convention ...
Question 89: Which GDPR requirement will present the most significant cha...
Question 90: SCENARIO Please use the following to answer the next questio...
Question 91: An online company's privacy practices vary due to the fact t...
Question 92: Please use the following to answer the next question: Due to...
Question 93: In which of the following cases, cited as an example by a WP...
Question 94: Jerry the Chief Marketing Officer for a sports apparel and t...
Question 95: Please use the following to answer the next question: Jack w...
Question 97: Under the Data Protection Law Enforcement Directive of the E...
Question 98: A data controller appoints a data protection officer. Which ...
Question 99: Which of the following is NOT exempt from the material scope...
Question 100: SCENARIO Please use the following to answer the next questio...
Question 101: SCENARIO Please use the following to answer the next questio...
Question 102: What type of data lies beyond the scope of the General Data ...
Question 103: Article 5(1)(b) of the GDPR states that personal data must b...
Question 104: According to the European Data Protection Board, data subjec...
Question 105: How is the retention of communications traffic data for law ...
Question 106: SCENARIO Please use the following to answer the next questio...
Question 107: What ruling did the Planet 49 CJEU judgment make regarding t...
Question 108: SCENARIO Please use the following to answer the next questio...
Question 109: SCENARIO Please use the following to answer the next questio...
Question 110: SCENARIO Please use the following to answer the next questio...
Question 111: Which of the following was the first to implement national l...
Question 112: Which institution has the power to adopt findings that confi...
Question 113: According to the E-Commerce Directive 2000/31/EC, where is t...
Question 114: In which of the following situations would an individual mos...
Question 115: If a data subject puts a complaint before a DPA and receives...
Question 116: As per the GDPR, which legal basis would be the most appropr...
Question 117: To which of the following parties does the territorial scope...
Question 118: SCENARIO Please use the following to answer the next questio...
Question 119: According to the GDPR, when should the processing of photogr...
Question 120: Please use the following to answer the next question: ProSto...
Question 121: Company X has entrusted the processing of their payroll data...
Question 122: Under Article 30 of the GDPR, controllers are required to ke...
Question 123: Which of the following does NOT have to be included in the r...
Question 124: When does the European Data Protection Board (EDPB) recommen...
Question 125: SCENARIO Please use the following to answer the next questio...
Question 126: Under the GDPR, which essential pieces of information must b...
Question 127: Under Article 30 of the GDPR, controllers are required to ke...
Question 128: According to the GDPR, how is pseudonymous personal data def...
Question 129: WP29's "Guidelines on Personal data breach notification unde...
Question 130: According to the GDPR, when should the processing of photogr...
Question 131: Which change was introduced by the 2009 amendments to the e-...
Question 132: Which type of personal data does the GDPR define as a "speci...
Question 133: A worker in a European Union (EU) member state has ceased hi...
Question 134: An organization receives a request multiple times from a dat...
Question 135: To receive a preliminary interpretation on provisions of the...
Question 136: When does the GDPR provide more latitude for a company to pr...
Question 137: SCENARIO Please use the following to answer the next questio...
Question 138: In which of the following situations would an individual mos...
Question 139: Two companies, Gellcoat and Freifish, make plans to launch a...
Question 140: Read the following steps: Discover which employees are acces...
Question 141: What permissions are required for a marketer to send an emai...
Question 142: SCENARIO Please use the following to answer the next questio...
Question 143: SCENARIO Please use the following to answer the next questio...
Question 144: SCENARIO Please use the following to answer the next questio...
Question 145: What is true of both the General Data Protection Regulation ...
Question 146: Data retention in the EU was underpinned by a legal framewor...
Question 147: Pursuant to Article 4(5) of the GDPR, data is considered "ps...
Question 148: SCENARIO Please use the following to answer the next questio...
Question 149: Which of the following countries will continue to enjoy adeq...
Question 150: SCENARIO Please use the following to answer the next questio...
Question 151: Which of the following would NOT be relevant when determinin...
Question 152: Which change was introduced by the 2009 amendments to the e-...
Question 153: What should a controller do after a data subject opts out of...
Question 154: Which aspect of the GDPR will likely have the most impact on...
Question 155: A homeowner has installed a motion-detecting surveillance sy...
Question 156: If a multi-national company wanted to conduct background che...
Question 157: According to the E-Commerce Directive 2000/31/EC, where is t...
Question 158: SCENARIO Please use the following to answer the next questio...
Question 159: Which statement is correct when considering the right to pri...
Question 160: Under Article 21 of the GDPR, a controller must stop profili...
Question 161: SCENARIO Please use the following to answer the next questio...
Question 162: How is the GDPR's position on consent MOST likely to affect ...
Question 163: Company X has entrusted the processing of their payroll data...
Question 164: SCENARIO Please use the following to answer the next questio...
Question 165: SCENARIO Please use the following to answer the next questio...
Question 166: Which of the following is the weakest lawful basis for proce...