<< Prev Question Next Question >>

Question 22/166

SCENARIO
Please use the following to answer the next question:
TripBliss Inc. is a travel service company which has lost substantial revenue over the last few years. Their new manager, Oliver, suspects that this is partly due to the company's outdated website. After doing some research, he meets with a sales representative from the up-and-coming IT company Techiva, hoping that they can design a new, cutting-edge website for TripBliss Inc.'s foundering business.
During negotiations, a Techiva representative describes a plan for gathering more customer information through detailed Questionaires, which could be used to tailor their preferences to specific travel destinations. TripBliss Inc. can choose any number of data categories - age, income, ethnicity - that would help them best accomplish their goals. Oliver loves this idea, but would also like to have some way of gauging how successful this approach is, especially since the Questionaires will require customers to provide explicit consent to having their data collected. The Techiva representative suggests that they also run a program to analyze the new website's traffic, in order to get a better understanding of how customers are using it. He explains his plan to place a number of cookies on customer devices. The cookies will allow the company to collect IP addresses and other information, such as the sites from which the customers came, how much time they spend on the TripBliss Inc. website, and which pages on the site they visit. All of this information will be compiled in log files, which Techiva will analyze by means of a special program. TripBliss Inc. would receive aggregate statistics to help them evaluate the website's effectiveness. Oliver enthusiastically engages Techiva for these services.
Techiva assigns the analytics portion of the project to longtime account manager Leon Santos. As is standard practice, Leon is given administrator rights to TripBliss Inc.'s website, and can authorize access to the log files gathered from it. Unfortunately for TripBliss Inc., however, Leon is taking on this new project at a time when his dissatisfaction with Techiva is at a high point. In order to take revenge for what he feels has been unfair treatment at the hands of the company, Leon asks his friend Fred, a hobby hacker, for help. Together they come up with the following plan: Fred will hack into Techiva's system and copy their log files onto a USB stick. Despite his initial intention to send the USB to the press and to the data protection authority in order to denounce Techiva, Leon experiences a crisis of conscience and ends up reconsidering his plan. He decides instead to securely wipe all the data from the USB stick and inform his manager that the company's system of access control must be reconsidered.
If TripBliss Inc. decides not to report the incident to the supervisory authority, what would be their BEST defense?

LEAVE A REPLY

Your email address will not be published. Required fields are marked *

Question List (166q)
Question 1: With the issue of consent, the GDPR allows member states som...
Question 2: What is true of both the General Data Protection Regulation ...
Question 3: What permissions are required for a marketer to send an emai...
Question 4: Which of the following is an accurate statement regarding th...
Question 5: How does the GDPR now define "processing"?...
Question 6: Which sentence best describes proper compliance for an inter...
Question 7: How is the retention of communications traffic data for law ...
Question 8: SCENARIO Please use the following to answer the next questio...
Question 9: The GDPR specifies fines that may be levied against data con...
Question 10: A U.S. company's website sells widgets. Which of the followi...
Question 11: SCENARIO Please use the following to answer the next questio...
Question 12: Higher fines are assessed for GDPR violations due to which o...
Question 13: For which of the following operations would an employer most...
Question 14: An employee of company ABCD has just noticed a memory stick ...
Question 15: What obligation does a data controller or processor have aft...
Question 16: SCENARIO Please use the following to answer the next questio...
Question 17: Under what circumstances would the GDPR apply to personal da...
Question 18: SCENARIO Please use the following to answer the next questio...
Question 19: SCENARIO Please use the following to answer the next questio...
Question 20: After leaving the EU under the terms of Brexit, the United K...
Question 21: SCENARIO Please use the following to answer the next questio...
Question 22: SCENARIO Please use the following to answer the next questio...
Question 23: SCENARIO Please use the following to answer the next questio...
Question 24: What is the consequence if a processor makes an independent ...
Question 25: Article 9 of the GDPR lists exceptions to the general prohib...
Question 26: Which area of privacy is a lead supervisory authority's (LSA...
Question 27: Which aspect of the GDPR will likely have the most impact on...
Question 28: A grade school is planning to use facial recognition to trac...
Question 29: Under the GDPR, which essential pieces of information must b...
Question 30: Under the GDPR, who would be LEAST likely to be allowed to e...
Question 31: Under the GDPR, who would be LEAST likely to be allowed to e...
Question 32: Under Article 21 of the GDPR, a controller must stop profili...
Question 33: SCENARIO Please use the following to answer the next questio...
Question 34: SCENARIO Please use the following to answer the next questio...
Question 35: An entity's website stores text files on EU users' computer ...
Question 36: Under Article 80(1) of the GDPR, individuals can elect to be...
Question 37: What term BEST describes the European model for data protect...
Question 38: SCENARIO Please use the following to answer the next questio...
Question 39: What is one major goal that the OECD Guidelines, Convention ...
Question 40: SCENARIO Please use the following to answer the next questio...
Question 41: What are the obligations of a processor that engages a sub-p...
Question 42: SCENARIO Please use the following to answer the next Questio...
Question 43: SCENARIO Please use the following to answer the next questio...
Question 44: In which scenario is a Controller most likely required to un...
Question 45: A U.S.-based online shop uses sophisticated software to trac...
Question 46: SCENARIO Please use the following to answer the next questio...
Question 47: SCENARIO Please use the following to answer the next questio...
Question 48: In relation to third countries and international organizatio...
Question 49: Please use the following to answer the next question: Jane S...
Question 50: When does the European Data Protection Board (EDPB) recommen...
Question 51: Why is advisable to avoid consent as a legal basis for an em...
Question 52: In 2016's Guidance, the United Kingdom's Information Commiss...
Question 53: Which of the following would require designating a data prot...
Question 54: According to the GDPR. Article 4(14). biometric data is defi...
Question 55: SCENARIO Please use the following to answer the next questio...
Question 56: SCENARIO Please use the following to answer the next questio...
Question 57: Company X has entrusted the processing of their payroll data...
Question 58: According to the GDPR, what is the main task of a Data Prote...
Question 59: Which type of personal data does the GDPR define as a "speci...
Question 60: SCENARIO Please use the following to answer the next questio...
Question 61: Under what circumstances would the GDPR apply to personal da...
Question 62: Select the answer below that accurately completes the follow...
Question 63: What term BEST describes the European model for data protect...
Question 64: Assuming that the "without undue delay" provision is followe...
Question 65: The GDPR forbids the practice of "forum shopping", which occ...
Question 66: WP29's "Guidelines on Personal data breach notification unde...
Question 67: Tanya is the Data Protection Officer for Curtains Inc., a GD...
Question 68: SCENARIO Please use the following to answer the next questio...
Question 69: Which of the following would MOST likely trigger the extrate...
Question 70: SCENARIO Please use the following to answer the next questio...
Question 71: What is the key difference between the European Council and ...
Question 72: According to Article 14 of the GDPR, how long does a control...
Question 73: Please use the following to answer the next question: Jane S...
Question 74: To which of the following parties does the territorial scope...
Question 75: What is an important difference between the European Court o...
Question 76: What are the obligations of a processor that engages a sub-p...
Question 77: SCENARIO Please use the following to answer the next questio...
Question 78: A well-known video production company, based in Spain but sp...
Question 79: SCENARIO Please use the following to answer the next questio...
Question 80: Assuming that the "without undue delay" provision is followe...
Question 81: The transparency principle is most directly related to which...
Question 82: The European Data Protection Board (EDPB) recommends measure...
Question 83: Based on GDPR Article 35, which of the following situations ...
Question 84: Which mechanism, new to the GDPR, now allows for the possibi...
Question 85: A well-known video production company, based in Spain but sp...
Question 86: SCENARIO Please use the following to answer the next questio...
Question 87: Which of the following would MOST likely trigger the extrate...
Question 88: What is one major goal that the OECD Guidelines, Convention ...
Question 89: Which GDPR requirement will present the most significant cha...
Question 90: SCENARIO Please use the following to answer the next questio...
Question 91: An online company's privacy practices vary due to the fact t...
Question 92: Please use the following to answer the next question: Due to...
Question 93: In which of the following cases, cited as an example by a WP...
Question 94: Jerry the Chief Marketing Officer for a sports apparel and t...
Question 95: Please use the following to answer the next question: Jack w...
Question 97: Under the Data Protection Law Enforcement Directive of the E...
Question 98: A data controller appoints a data protection officer. Which ...
Question 99: Which of the following is NOT exempt from the material scope...
Question 100: SCENARIO Please use the following to answer the next questio...
Question 101: SCENARIO Please use the following to answer the next questio...
Question 102: What type of data lies beyond the scope of the General Data ...
Question 103: Article 5(1)(b) of the GDPR states that personal data must b...
Question 104: According to the European Data Protection Board, data subjec...
Question 105: How is the retention of communications traffic data for law ...
Question 106: SCENARIO Please use the following to answer the next questio...
Question 107: What ruling did the Planet 49 CJEU judgment make regarding t...
Question 108: SCENARIO Please use the following to answer the next questio...
Question 109: SCENARIO Please use the following to answer the next questio...
Question 110: SCENARIO Please use the following to answer the next questio...
Question 111: Which of the following was the first to implement national l...
Question 112: Which institution has the power to adopt findings that confi...
Question 113: According to the E-Commerce Directive 2000/31/EC, where is t...
Question 114: In which of the following situations would an individual mos...
Question 115: If a data subject puts a complaint before a DPA and receives...
Question 116: As per the GDPR, which legal basis would be the most appropr...
Question 117: To which of the following parties does the territorial scope...
Question 118: SCENARIO Please use the following to answer the next questio...
Question 119: According to the GDPR, when should the processing of photogr...
Question 120: Please use the following to answer the next question: ProSto...
Question 121: Company X has entrusted the processing of their payroll data...
Question 122: Under Article 30 of the GDPR, controllers are required to ke...
Question 123: Which of the following does NOT have to be included in the r...
Question 124: When does the European Data Protection Board (EDPB) recommen...
Question 125: SCENARIO Please use the following to answer the next questio...
Question 126: Under the GDPR, which essential pieces of information must b...
Question 127: Under Article 30 of the GDPR, controllers are required to ke...
Question 128: According to the GDPR, how is pseudonymous personal data def...
Question 129: WP29's "Guidelines on Personal data breach notification unde...
Question 130: According to the GDPR, when should the processing of photogr...
Question 131: Which change was introduced by the 2009 amendments to the e-...
Question 132: Which type of personal data does the GDPR define as a "speci...
Question 133: A worker in a European Union (EU) member state has ceased hi...
Question 134: An organization receives a request multiple times from a dat...
Question 135: To receive a preliminary interpretation on provisions of the...
Question 136: When does the GDPR provide more latitude for a company to pr...
Question 137: SCENARIO Please use the following to answer the next questio...
Question 138: In which of the following situations would an individual mos...
Question 139: Two companies, Gellcoat and Freifish, make plans to launch a...
Question 140: Read the following steps: Discover which employees are acces...
Question 141: What permissions are required for a marketer to send an emai...
Question 142: SCENARIO Please use the following to answer the next questio...
Question 143: SCENARIO Please use the following to answer the next questio...
Question 144: SCENARIO Please use the following to answer the next questio...
Question 145: What is true of both the General Data Protection Regulation ...
Question 146: Data retention in the EU was underpinned by a legal framewor...
Question 147: Pursuant to Article 4(5) of the GDPR, data is considered "ps...
Question 148: SCENARIO Please use the following to answer the next questio...
Question 149: Which of the following countries will continue to enjoy adeq...
Question 150: SCENARIO Please use the following to answer the next questio...
Question 151: Which of the following would NOT be relevant when determinin...
Question 152: Which change was introduced by the 2009 amendments to the e-...
Question 153: What should a controller do after a data subject opts out of...
Question 154: Which aspect of the GDPR will likely have the most impact on...
Question 155: A homeowner has installed a motion-detecting surveillance sy...
Question 156: If a multi-national company wanted to conduct background che...
Question 157: According to the E-Commerce Directive 2000/31/EC, where is t...
Question 158: SCENARIO Please use the following to answer the next questio...
Question 159: Which statement is correct when considering the right to pri...
Question 160: Under Article 21 of the GDPR, a controller must stop profili...
Question 161: SCENARIO Please use the following to answer the next questio...
Question 162: How is the GDPR's position on consent MOST likely to affect ...
Question 163: Company X has entrusted the processing of their payroll data...
Question 164: SCENARIO Please use the following to answer the next questio...
Question 165: SCENARIO Please use the following to answer the next questio...
Question 166: Which of the following is the weakest lawful basis for proce...