nerdexam
IAPP

CIPP-E · Question #103

To provide evidence of GDPR compliance, a company performs an internal audit. As a result, it finds a data base, password-protected, listing all the social network followers of the client. Regarding…

The correct answer is B. Non-compliant, because the storage of the data exceeds the tasks contractually authorized by the. The GDPR requires that the processor only processes personal data on behalf of the controller and according to the controller's instructions. The agreement between the controller and the processor must include provisions that ensure that the processor does not process personal…

Compliance with European Data Protection Law

Question

To provide evidence of GDPR compliance, a company performs an internal audit. As a result, it finds a data base, password-protected, listing all the social network followers of the client. Regarding the domain of the controller-processor relationships, how is this situation considered?

Options

  • ACompliant with the security principle, because the data base is password-protected.
  • BNon-compliant, because the storage of the data exceeds the tasks contractually authorized by the
  • CNot applicable, because the data base is password protected, and therefore is not at risk of
  • DCompliant with the storage limitation principle, so long as the internal auditor permanently deletes

How the community answered

(36 responses)
  • A
    6% (2)
  • B
    56% (20)
  • C
    28% (10)
  • D
    11% (4)

Explanation

The GDPR requires that the processor only processes personal data on behalf of the controller and according to the controller's instructions. The agreement between the controller and the processor must include provisions that ensure that the processor does not process personal data for any other purposes or in a manner that is inconsistent with the controller's instructions. Therefore, if the processor stores personal data that is not necessary for the performance of the contract with the controller, such as the social network followers of the client, this is a breach of the GDPR and the processor may be fined. The fact that the data base is password-protected does not affect the applicability of the GDPR or the security principle, as the data is still personal data that can identify data subjects. The storage limitation principle also requires that personal data be kept for no longer than is necessary for the purposes for which the personal data are processed, so deleting the data base after the audit does not make the situation compliant.

Topics

#controller-processor relationship#purpose limitation#unauthorized processing#GDPR compliance

Community Discussion

No community discussion yet for this question.

Full CIPP-E Practice