Valid GDPR Dumps shared by ExamDiscuss.com for Helping Passing GDPR Exam! ExamDiscuss.com now offer the newest GDPR exam dumps, the ExamDiscuss.com GDPR exam questions have been updated and answers have been corrected get the newest ExamDiscuss.com GDPR dumps with Test Engine here:
Scenario: ChatBubbleis a software company that stores personal data, includingusernames, emails, and passwords. Last month, an attacker gained access to ChatBubble's system, but the personal datawas encrypted, preventing unauthorized access. Question: Should thedata subjects be notifiedin this case?
Correct Answer: C
UnderArticle 34(3)(a) of GDPR, if personal datais encrypted or otherwise protected, notification to data subjectsis not requiredunless the risk is high. * Option C is correctbecauseencryption renders the data unintelligible to unauthorized parties, reducing risk. * Option A is incorrectbecausenot all breaches require data subject notification-only those posing high risks. * Option B is incorrectbecausethe number of affected individuals does not determine notification requirements. * Option D is incorrectbecausenotification is based on risk assessment, not supervisory authority requests alone. References: * GDPR Article 34(3)(a)(No notification required if encryption makes data inaccessible) * Recital 86(Notification is necessary only if data loss poses a significant risk)