<< Prev Question Next Question >>

Question 143/166

SCENARIO
Please use the following to answer the next question:
Joe started the Gummy Bear Company in 2000 from his home in Vermont, USA. Today, it is a multi-billion-dollar candy company operating in every continent. All of the company's IT servers are located in Vermont. This year Joe hires his son Ben to join the company and head up Project Big, which is a major marketing strategy to triple gross revenue in just 5 years. Ben graduated with a PhD in computer software from a top university. Ben decided to join his father's company, but is also secretly working on launching a new global online dating website company called Ben Knows Best.
Ben is aware that the Gummy Bear Company has millions of customers and believes that many of them might also be interested in finding their perfect match. For Project Big, Ben redesigns the company's online web portal and requires customers in the European Union and elsewhere to provide additional personal information in order to remain a customer. Project Ben begins collecting data about customers' philosophical beliefs, political opinions and marital status.
If a customer identifies as single, Ben then copies all of that customer's personal data onto a separate database for Ben Knows Best. Ben believes that he is not doing anything wrong, because he explicitly asks each customer to give their consent by requiring them to check a box before accepting their information. As Project Big is an important project, the company also hires a first year college student named Sam, who is studying computer science to help Ben out.
Ben calls out and Sam comes across the Ben Knows Best database. Sam is planning on going to Ireland over Spring Beak with 10 of his friends, so he copies all of the customer information of people that reside in Ireland so that he and his friends can contact people when they are in Ireland.
Joe also hires his best friend's daughter, Alice, who just graduated from law school in the U.S., to be the company's new General Counsel. Alice has heard about the GDPR, so she does some research on it. Alice approaches Joe and informs him that she has drafted up Binding Corporate Rules for everyone in the company to follow, as it is important for the company to have in place a legal mechanism to transfer data internally from the company's operations in the European Union to the U.S.
Joe believes that Alice is doing a great job, and informs her that she will also be in-charge of handling a major lawsuit that has been brought against the company in federal court in the U.S. To prepare for the lawsuit, Alice instructs the company's IT department to make copies of the computer hard drives from the entire global sales team, including the European Union, and send everything to her so that she can review everyone's information. Alice believes that Joe will be happy that she did the first level review, as it will save the company a lot of money that would otherwise be paid to its outside law firm.
As a result of Sam's actions, the Gummy Bear Company potentially violated Articles 33 and 34 of the GDPR and will be required to do what?

LEAVE A REPLY

Your email address will not be published. Required fields are marked *

Question List (166q)
Question 1: With the issue of consent, the GDPR allows member states som...
Question 2: What is true of both the General Data Protection Regulation ...
Question 3: What permissions are required for a marketer to send an emai...
Question 4: Which of the following is an accurate statement regarding th...
Question 5: How does the GDPR now define "processing"?...
Question 6: Which sentence best describes proper compliance for an inter...
Question 7: How is the retention of communications traffic data for law ...
Question 8: SCENARIO Please use the following to answer the next questio...
Question 9: The GDPR specifies fines that may be levied against data con...
Question 10: A U.S. company's website sells widgets. Which of the followi...
Question 11: SCENARIO Please use the following to answer the next questio...
Question 12: Higher fines are assessed for GDPR violations due to which o...
Question 13: For which of the following operations would an employer most...
Question 14: An employee of company ABCD has just noticed a memory stick ...
Question 15: What obligation does a data controller or processor have aft...
Question 16: SCENARIO Please use the following to answer the next questio...
Question 17: Under what circumstances would the GDPR apply to personal da...
Question 18: SCENARIO Please use the following to answer the next questio...
Question 19: SCENARIO Please use the following to answer the next questio...
Question 20: After leaving the EU under the terms of Brexit, the United K...
Question 21: SCENARIO Please use the following to answer the next questio...
Question 22: SCENARIO Please use the following to answer the next questio...
Question 23: SCENARIO Please use the following to answer the next questio...
Question 24: What is the consequence if a processor makes an independent ...
Question 25: Article 9 of the GDPR lists exceptions to the general prohib...
Question 26: Which area of privacy is a lead supervisory authority's (LSA...
Question 27: Which aspect of the GDPR will likely have the most impact on...
Question 28: A grade school is planning to use facial recognition to trac...
Question 29: Under the GDPR, which essential pieces of information must b...
Question 30: Under the GDPR, who would be LEAST likely to be allowed to e...
Question 31: Under the GDPR, who would be LEAST likely to be allowed to e...
Question 32: Under Article 21 of the GDPR, a controller must stop profili...
Question 33: SCENARIO Please use the following to answer the next questio...
Question 34: SCENARIO Please use the following to answer the next questio...
Question 35: An entity's website stores text files on EU users' computer ...
Question 36: Under Article 80(1) of the GDPR, individuals can elect to be...
Question 37: What term BEST describes the European model for data protect...
Question 38: SCENARIO Please use the following to answer the next questio...
Question 39: What is one major goal that the OECD Guidelines, Convention ...
Question 40: SCENARIO Please use the following to answer the next questio...
Question 41: What are the obligations of a processor that engages a sub-p...
Question 42: SCENARIO Please use the following to answer the next Questio...
Question 43: SCENARIO Please use the following to answer the next questio...
Question 44: In which scenario is a Controller most likely required to un...
Question 45: A U.S.-based online shop uses sophisticated software to trac...
Question 46: SCENARIO Please use the following to answer the next questio...
Question 47: SCENARIO Please use the following to answer the next questio...
Question 48: In relation to third countries and international organizatio...
Question 49: Please use the following to answer the next question: Jane S...
Question 50: When does the European Data Protection Board (EDPB) recommen...
Question 51: Why is advisable to avoid consent as a legal basis for an em...
Question 52: In 2016's Guidance, the United Kingdom's Information Commiss...
Question 53: Which of the following would require designating a data prot...
Question 54: According to the GDPR. Article 4(14). biometric data is defi...
Question 55: SCENARIO Please use the following to answer the next questio...
Question 56: SCENARIO Please use the following to answer the next questio...
Question 57: Company X has entrusted the processing of their payroll data...
Question 58: According to the GDPR, what is the main task of a Data Prote...
Question 59: Which type of personal data does the GDPR define as a "speci...
Question 60: SCENARIO Please use the following to answer the next questio...
Question 61: Under what circumstances would the GDPR apply to personal da...
Question 62: Select the answer below that accurately completes the follow...
Question 63: What term BEST describes the European model for data protect...
Question 64: Assuming that the "without undue delay" provision is followe...
Question 65: The GDPR forbids the practice of "forum shopping", which occ...
Question 66: WP29's "Guidelines on Personal data breach notification unde...
Question 67: Tanya is the Data Protection Officer for Curtains Inc., a GD...
Question 68: SCENARIO Please use the following to answer the next questio...
Question 69: Which of the following would MOST likely trigger the extrate...
Question 70: SCENARIO Please use the following to answer the next questio...
Question 71: What is the key difference between the European Council and ...
Question 72: According to Article 14 of the GDPR, how long does a control...
Question 73: Please use the following to answer the next question: Jane S...
Question 74: To which of the following parties does the territorial scope...
Question 75: What is an important difference between the European Court o...
Question 76: What are the obligations of a processor that engages a sub-p...
Question 77: SCENARIO Please use the following to answer the next questio...
Question 78: A well-known video production company, based in Spain but sp...
Question 79: SCENARIO Please use the following to answer the next questio...
Question 80: Assuming that the "without undue delay" provision is followe...
Question 81: The transparency principle is most directly related to which...
Question 82: The European Data Protection Board (EDPB) recommends measure...
Question 83: Based on GDPR Article 35, which of the following situations ...
Question 84: Which mechanism, new to the GDPR, now allows for the possibi...
Question 85: A well-known video production company, based in Spain but sp...
Question 86: SCENARIO Please use the following to answer the next questio...
Question 87: Which of the following would MOST likely trigger the extrate...
Question 88: What is one major goal that the OECD Guidelines, Convention ...
Question 89: Which GDPR requirement will present the most significant cha...
Question 90: SCENARIO Please use the following to answer the next questio...
Question 91: An online company's privacy practices vary due to the fact t...
Question 92: Please use the following to answer the next question: Due to...
Question 93: In which of the following cases, cited as an example by a WP...
Question 94: Jerry the Chief Marketing Officer for a sports apparel and t...
Question 95: Please use the following to answer the next question: Jack w...
Question 97: Under the Data Protection Law Enforcement Directive of the E...
Question 98: A data controller appoints a data protection officer. Which ...
Question 99: Which of the following is NOT exempt from the material scope...
Question 100: SCENARIO Please use the following to answer the next questio...
Question 101: SCENARIO Please use the following to answer the next questio...
Question 102: What type of data lies beyond the scope of the General Data ...
Question 103: Article 5(1)(b) of the GDPR states that personal data must b...
Question 104: According to the European Data Protection Board, data subjec...
Question 105: How is the retention of communications traffic data for law ...
Question 106: SCENARIO Please use the following to answer the next questio...
Question 107: What ruling did the Planet 49 CJEU judgment make regarding t...
Question 108: SCENARIO Please use the following to answer the next questio...
Question 109: SCENARIO Please use the following to answer the next questio...
Question 110: SCENARIO Please use the following to answer the next questio...
Question 111: Which of the following was the first to implement national l...
Question 112: Which institution has the power to adopt findings that confi...
Question 113: According to the E-Commerce Directive 2000/31/EC, where is t...
Question 114: In which of the following situations would an individual mos...
Question 115: If a data subject puts a complaint before a DPA and receives...
Question 116: As per the GDPR, which legal basis would be the most appropr...
Question 117: To which of the following parties does the territorial scope...
Question 118: SCENARIO Please use the following to answer the next questio...
Question 119: According to the GDPR, when should the processing of photogr...
Question 120: Please use the following to answer the next question: ProSto...
Question 121: Company X has entrusted the processing of their payroll data...
Question 122: Under Article 30 of the GDPR, controllers are required to ke...
Question 123: Which of the following does NOT have to be included in the r...
Question 124: When does the European Data Protection Board (EDPB) recommen...
Question 125: SCENARIO Please use the following to answer the next questio...
Question 126: Under the GDPR, which essential pieces of information must b...
Question 127: Under Article 30 of the GDPR, controllers are required to ke...
Question 128: According to the GDPR, how is pseudonymous personal data def...
Question 129: WP29's "Guidelines on Personal data breach notification unde...
Question 130: According to the GDPR, when should the processing of photogr...
Question 131: Which change was introduced by the 2009 amendments to the e-...
Question 132: Which type of personal data does the GDPR define as a "speci...
Question 133: A worker in a European Union (EU) member state has ceased hi...
Question 134: An organization receives a request multiple times from a dat...
Question 135: To receive a preliminary interpretation on provisions of the...
Question 136: When does the GDPR provide more latitude for a company to pr...
Question 137: SCENARIO Please use the following to answer the next questio...
Question 138: In which of the following situations would an individual mos...
Question 139: Two companies, Gellcoat and Freifish, make plans to launch a...
Question 140: Read the following steps: Discover which employees are acces...
Question 141: What permissions are required for a marketer to send an emai...
Question 142: SCENARIO Please use the following to answer the next questio...
Question 143: SCENARIO Please use the following to answer the next questio...
Question 144: SCENARIO Please use the following to answer the next questio...
Question 145: What is true of both the General Data Protection Regulation ...
Question 146: Data retention in the EU was underpinned by a legal framewor...
Question 147: Pursuant to Article 4(5) of the GDPR, data is considered "ps...
Question 148: SCENARIO Please use the following to answer the next questio...
Question 149: Which of the following countries will continue to enjoy adeq...
Question 150: SCENARIO Please use the following to answer the next questio...
Question 151: Which of the following would NOT be relevant when determinin...
Question 152: Which change was introduced by the 2009 amendments to the e-...
Question 153: What should a controller do after a data subject opts out of...
Question 154: Which aspect of the GDPR will likely have the most impact on...
Question 155: A homeowner has installed a motion-detecting surveillance sy...
Question 156: If a multi-national company wanted to conduct background che...
Question 157: According to the E-Commerce Directive 2000/31/EC, where is t...
Question 158: SCENARIO Please use the following to answer the next questio...
Question 159: Which statement is correct when considering the right to pri...
Question 160: Under Article 21 of the GDPR, a controller must stop profili...
Question 161: SCENARIO Please use the following to answer the next questio...
Question 162: How is the GDPR's position on consent MOST likely to affect ...
Question 163: Company X has entrusted the processing of their payroll data...
Question 164: SCENARIO Please use the following to answer the next questio...
Question 165: SCENARIO Please use the following to answer the next questio...
Question 166: Which of the following is the weakest lawful basis for proce...