<< Prev Question Next Question >>

Question 85/114

SCENARIO
Please use the following to answer the next question:
Louis, a long-time customer of Bedrock Insurance, was involved in a minor car accident a few months ago. Although no one was hurt, Louis has been plagued by texts and calls from a company called Accidentable offering to help him recover compensation for personal injury. Louis has heard about insurance companies selling customers' data to third parties, and he's convinced that Accidentable must have gotten his information from Bedrock Insurance.
Louis has also been receiving an increased amount of marketing information from Bedrock, trying to sell him their full range of their insurance policies.
Perturbed by this, Louis has started looking at price comparison sites on the internet and has been shocked to find that other insurers offer much cheaper rates than Bedrock, even though he has been a loyal customer for many years. When his Bedrock policy comes up for renewal, he decides to switch to Zantrum Insurance.
In order to activate his new insurance policy, Louis needs to supply Zantrum with information about his No Claims bonus, his vehicle and his driving history. After researching his rights under the GDPR, he writes to ask Bedrock to transfer his information directly to Zantrum. He also takes this opportunity to ask Bedrock to stop using his personal data for marketing purposes.
Bedrock supplies Louis with a PDF and XML (Extensible Markup Language) versions of his No Claims Certificate, but tells Louis it cannot transfer his data directly to Zantrum as this is not technically feasible. Bedrock also explains that Louis's contract included a provision whereby Louis agreed that his data could be used for marketing purposes; according to Bedrock, it is too late for Louis to change his mind about this. It angers Louis when he recalls the wording of the contract, which was filled with legal jargon and very confusing.
In the meantime, Louis is still receiving unwanted calls from Accidentable Insurance. He writes to Accidentable to ask for the name of the organization that supplied his details to them. He warns Accidentable that he plans to complain to the data protection authority, because he thinks their company has been using his data unlawfully. His letter states that he does not want his data being used by them in any way.
Accidentable's response letter confirms Louis's suspicions. Accidentable is Bedrock Insurance's wholly owned subsidiary, and they received information about Louis's accident from Bedrock shortly after Louis submitted his accident claim. Accidentable assures Louis that there has been no breach of the GDPR, as Louis's contract included, a provision in which he agreed to share his information with Bedrock's affiliates for business purposes.
Louis is disgusted by the way in which he has been treated by Bedrock, and writes to them insisting that all his information be erased from their computer system.
After Louis has exercised his right to restrict the use of his data, under what conditions would Accidentable have grounds for refusing to comply?

LEAVE A REPLY

Your email address will not be published. Required fields are marked *

Question List (114q)
Question 1: According to the GDPR, what is the main task of a Data Prote...
Question 2: The GDPR forbids the practice of "forum shopping", which occ...
Question 3: Which of the following is NOT an explicit right granted to d...
Question 4: SCENARIO Please use the following to answer the next questio...
Question 5: If a company chooses to ground an international data transfe...
Question 6: How is the GDPR's position on consent MOST likely to affect ...
Question 7: SCENARIO Please use the following to answer the next questio...
Question 8: SCENARIO Please use the following to answer the next questio...
Question 9: Which of the following would NOT be relevant when determinin...
Question 10: SCENARIO Please use the following to answer the next questio...
Question 11: In which case would a controller who has undertaken a DPIA m...
Question 12: Which of the following would require designating a data prot...
Question 13: An entity's website stores text files on EU users' computer ...
Question 14: The European Parliament jointly exercises legislative and bu...
Question 15: When assessing the level of risk created by a data breach, w...
Question 16: SCENARIO Please use the following to answer the next questio...
Question 17: Pursuant to Article 17 and EDPB Guidelines S'2019 on RTBF cr...
Question 18: When may browser settings be relied upon for the lawful appl...
Question 19: Which of the following is NOT recognized as being a common c...
Question 20: SCENARIO Please use the following to answer the next questio...
Question 21: According to Article 14 of the GDPR, how long does a control...
Question 22: SCENARIO Please use the following to answer the next questio...
Question 23: In addition to the European Commission, who can adopt standa...
Question 24: What must be included in a written agreement between the con...
Question 25: Under which of the following conditions does the General Dat...
Question 26: After leaving the EU under the terms of Brexit, the United K...
Question 27: SCENARIO Please use the following to answer the next questio...
Question 28: What is the consequence if a processor makes an independent ...
Question 29: In the Planet 49 case, what was the man judgement of the Coo...
Question 30: SCENARIO Please use the following to answer the next questio...
Question 31: Based on GDPR Article 35, which of the following situations ...
Question 32: Under the GDPR, where personal data is not obtained directly...
Question 33: If a multi-national company wanted to conduct background che...
Question 34: Which of the following Convention 108+ principles, as amende...
Question 35: SCENARIO Please use the following to answer the next questio...
Question 36: What type of data lies beyond the scope of the General Data ...
Question 37: SCENARIO Please use the following to answer the next questio...
Question 38: Which aspect of the GDPR will likely have the most impact on...
Question 39: A company in France suffers a robbery over the weekend owing...
Question 40: Which of the following was the first legally binding interna...
Question 41: Articles 13 and 14 of the GDPR provide details on the obliga...
Question 42: A data controller appoints a data protection officer. Which ...
Question 43: What is the main task of the European Data Protection Board?...
Question 44: According to Article 84 of the GDPR, the rules on penalties ...
Question 45: SCENARIO Please use the following to answer the next questio...
Question 46: SCENARIO Please use the following to answer the next questio...
Question 47: Which of the following entities would most likely be exempt ...
Question 48: In the event of a data breach, which type of information are...
Question 49: Which GDPR requirement will present the most significant cha...
Question 50: As a result of the European Court of Justice's ruling in the...
Question 51: Two companies, Gellcoat and Freifish, make plans to launch a...
Question 52: Which marketing-related activity is least likely to be cover...
Question 53: According to the GDPR, how is pseudonymous personal data def...
Question 54: Under Article 80(1) of the GDPR, individuals can elect to be...
Question 55: SCENARIO Please use the following to answer the next questio...
Question 56: According to the European Data Protection Board, which of th...
Question 57: SCENARIO Please use the following to answer the next questio...
Question 58: SCENARIO Please use the following to answer the next questio...
Question 59: Which of the following does NOT have to be included in the r...
Question 60: According to the GDPR, when should the processing of photogr...
Question 61: A U.S.-based online shop uses sophisticated software to trac...
Question 62: SCENARIO Please use the following to answer the next questio...
Question 63: Which EU institution is vested with the competence to propos...
Question 64: If two controllers act as joint controllers pursuant to Arti...
Question 65: SCENARIO Please use the following to answer the next questio...
Question 66: To provide evidence of GDPR compliance, a company performs a...
Question 67: A company would like to implement CCTV monitoring in its off...
Question 68: What permissions are required for a marketer to send an emai...
Question 69: Which of the following is an example of direct marketing tha...
Question 70: A company is hesitating between Binding Corporate Rules and ...
Question 71: SCENARIO Please use the following to answer the next questio...
Question 72: SCENARIO Please use the following to answer the next questio...
Question 73: Which type of personal data does the GDPR define as a "speci...
Question 74: What was the aim of the European Data Protection Directive 9...
Question 75: Which of the following would most likely NOT be covered by t...
Question 76: What was the main failing of Convention 108 that led to the ...
Question 77: Under the GDPR, which of the following is true in regard to ...
Question 78: To which of the following parties does the territorial scope...
Question 79: According to the European Data Protection Board, data subjec...
Question 80: When does the GDPR provide more latitude for a company to pr...
Question 81: When hiring a data processor, which action would a data cont...
Question 82: Which of the following would MOST likely trigger the extrate...
Question 83: SCENARIO Please use the following to answer the next questio...
Question 84: A grade school is planning to use facial recognition to trac...
Question 85: SCENARIO Please use the following to answer the next questio...
Question 86: SCENARIO Please use the following to answer the next questio...
Question 87: Higher fines are assessed for GDPR violations due to which o...
Question 88: Which area of privacy is a lead supervisory authority's (LSA...
Question 89: Read the following steps: Discover which employees are acces...
Question 90: If a French controller has a car-sharing app available only ...
Question 91: Which of the following is the weakest lawful basis for proce...
Question 92: An online company's privacy practices vary due to the fact t...
Question 93: Which sentence BEST summarizes the concepts of "fairness," "...
Question 94: When collecting personal data in a European Union (EU) membe...
Question 95: SCENARIO Please use the following to answer the next questio...
Question 96: SCENARIO Please use the following to answer the next questio...
Question 97: A key component of the OECD Guidelines is the "Individual Pa...
Question 98: Under what circumstances might the "soft opt-in" rule apply ...
Question 99: Which of the following is NOT exempt from the material scope...
Question 100: What is an important difference between the European Court o...
Question 101: What are the obligations of a processor that engages a sub-p...
Question 102: Which kind of privacy notice, originally advocated by the Ar...
Question 103: Which of the following countries will continue to enjoy adeq...
Question 104: Which mechanism, new to the GDPR, now allows for the possibi...
Question 105: Bioface is a company based in the United States. It has no s...
Question 106: SCENARIO Please use the following to answer the next questio...
Question 107: A news website based m (he United Slates reports primarily o...
Question 108: According to the E-Commerce Directive 2000/31/EC, where is t...
Question 109: What term BEST describes the European model for data protect...
Question 110: In which of the following cases, cited as an example by a WP...
Question 111: A U.S. company's website sells widgets. Which of the followi...
Question 112: Which judicial body makes decisions on actions taken by indi...
Question 113: How is the retention of communications traffic data for law ...
Question 114: WP29's "Guidelines on Personal data breach notification unde...