<< Prev Question Next Question >>

Question 5/41

Scenario 7: EduCCS is an online education platform based in Netherlands. EduCCS helps organizations find, manage, and deliver their corporate training. Most of EduCCS's clients are EU residents. EduCCS is one of the few education organizations that have achieved GDPR compliance since 2019. Their DPO is a full-time employee who has been engaged in most data protection processes within the organization. In addition to facilitating GDPR compliance, the DPO acts as an intermediary point between EduCCS and other relevant interested parties. EduCCS's users can benefit from the variety of up-to-date training library and the possibility of accessing it through their phones, tablets, or computers. EduCCS's services are offered through two main platforms: online learning and digital training. To use one of these platforms, users should sign on EduCCS's website by providing their personal information. Online learning is a platform in which employees of other organizations can search for and request the training they need. Through its digital training platform, on the other hand, EduCCS manages the entire training and education program for other organizations.
Organizations that need this type of service need to provide information about their core activities and areas where training sessions are needed. This information is then analyzed by EduCCS and a customized training program is provided. In the beginning, all IT-related services were managed by two employees of EduCCS.
However, after acquiring a large number of clients, managing these services became challenging That is why EduCCS decided to outsource the IT service function to X-Tech. X-Tech provides IT support and is responsible for ensuring the security of EduCCS's network and systems. In addition, X-Tech stores and archives EduCCS's information including their training programs and clients' and employees' data. Recently, X-Tech made headlines in the technology press for being a victim of a phishing attack. A group of three attackers hacked X-Tech's systems via a phishing campaign which targeted the employees of the Marketing Department. By compromising X-Tech's mail server, hackers were able to gain access to more than 200 computer systems. Consequently, access to the networks of EduCCS's clients was also allowed. Using EduCCS's employee accounts, attackers installed a remote access tool on EduCCS's compromised systems.
By doing so, they gained access to personal information of EduCCS's clients, training programs, and other information stored in its online payment system. The attack was detected by X-Tech's system administrator.
After detecting unusual activity in X-Tech's network, they immediately reported it to the incident management team of the company. One week after being notified about the personal data breach, EduCCS communicated the incident to the supervisory authority with a document that outlined the reasons for the delay revealing that due to the lack of regular testing or modification, their incident response plan was not adequately preparedto handle such an attack.Based on this scenario, answer the following question:
Question:
Based on scenario 7, due to the attack, personal data ofEduCCS' clients(such as names, email addresses, and phone numbers) were unlawfully accessed.
According to GDPR,when must EduCCS inform its clientsabout this personal data breach?

LEAVE A REPLY

Your email address will not be published. Required fields are marked *

Question List (41q)
Question 1: Scenario5: Recpond is a German employment recruiting company...
Question 2: Scenario7: Scenario 7: EduCCS is an online education platfor...
Question 3: Question: According toArticle 82 of GDPR, when must aprocess...
Question 4: Scenario1: MED is a healthcare provider located in Norway. I...
Question 5: Scenario 7: EduCCS is an online education platform based in ...
Question 6: Scenario:2 Soyled is a retail company that sells a wide rang...
Question 7: Scenario 8:MA store is an online clothing retailer founded i...
Question 8: Question: All the statements below regarding thelawfulness o...
Question 9: Scenario:2 Soyled is a retail company that sells a wide rang...
Question 10: Scenario3: COR Bank is an international banking group that o...
Question 11: Scenario5: Recpond is a German employment recruiting company...
Question 12: Scenario 9:Soin is a French travel agency with the largest n...
Question 13: Scenario: Socianis a softwareused to collect medical records...
Question 14: When pseudonymization is used in a dataset, the data is divi...
Question 15: Question: Based onArticle 58 of GDPR, whatpowersmust thesupe...
Question 16: Scenario5: Recpond is a German employment recruiting company...
Question 17: Scenario1: MED is a healthcare provider located in Norway. I...
Question 18: Scenario: Aclinical research organizationcollects and proces...
Question 19: Scenario: PickFoodis an onlinefood delivery servicethat allo...
Question 20: Scenario 7: EduCCS is an online education platform based in ...
Question 21: Scenario4: Berc is a pharmaceutical company headquartered in...
Question 22: Scenario4: Berc is a pharmaceutical company headquartered in...
Question 23: Scenario3: COR Bank is an international banking group that o...
Question 24: Scenario 8:MA store is an online clothing retailer founded i...
Question 25: Question: UnderGDPR, the controller must demonstrate thatdat...
Question 26: Scenario: BookStis anonline bookshopthat collectspersonal da...
Question 27: An organization suffered a personal data breach. The attacke...
Question 28: Question: What is therole of the DPO in a DPIA?...
Question 29: Scenario: ChatBubbleis a software company that stores person...
Question 30: Scenario:2 Soyled is a retail company that sells a wide rang...
Question 31: Scenario3: COR Bank is an international banking group that o...
Question 32: Scenario4: Berc is a pharmaceutical company headquartered in...
Question 33: Question: What is themain purpose of conducting a DPIA?...
Question 34: Question: Which of the following options is theDPO's respons...
Question 35: Scenario 9:Soin is a French travel agency with the largest n...
Question 36: Question: What can beincludedin a DPIA?...
Question 37: Scenario4: Berc is a pharmaceutical company headquartered in...
Question 38: Scenario: A financial institution collectsbiometric data of ...
Question 39: Scenario 9:Soin is a French travel agency with the largest n...
Question 40: Question: You work in a company that providestraining servic...
Question 41: Scenario: An organization has been using astorage transfer s...