nerdexam
IAPP

CIPP-E · Question #188

Pursuant to Article 4(5) of the GDPR, data is considered "pseudonymized" if?

The correct answer is A. It cannot be attributed to a data subject without the use of additional information. According to Article 4(5) of the GDPR, pseudonymization is "the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is…

Legislative Framework

Question

Pursuant to Article 4(5) of the GDPR, data is considered "pseudonymized" if?

Options

  • AIt cannot be attributed to a data subject without the use of additional information.
  • BIt cannot be attributed to a person under any circumstances.
  • CIt can only be attributed to a person by the controller.
  • DIt can only be attributed to a person by a third party.

How the community answered

(45 responses)
  • A
    93% (42)
  • B
    2% (1)
  • C
    4% (2)

Explanation

According to Article 4(5) of the GDPR, pseudonymization is "the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the personal data are not attributed to an identified or identifiable natural person." Therefore, option A is the correct definition of pseudonymization. Option B is incorrect because pseudonymized data can still be attributed to a person with the use of additional information. Option C is incorrect because pseudonymization does not depend on who can attribute the data to a person, but on how the data is processed.

Topics

#pseudonymization#GDPR Article 4#personal data definition#re-identification risk

Community Discussion

No community discussion yet for this question.

Full CIPP-E Practice