nerdexam
IAPP

CIPP-E · Question #234

It a company receives an anonymous email demanding ransom for the stolen personal data of its clients, what must the company do next, per GDPR requirements'3

The correct answer is C. Send a notification to the competent supervisory authority describing the incident. You've hit your limit · resets 12:50am (America/New_York)

Compliance with European Data Protection Law

Question

It a company receives an anonymous email demanding ransom for the stolen personal data of its clients, what must the company do next, per GDPR requirements'3

Options

  • ANotify the police and Tile a criminal complaint about the incident
  • BStart an investigation to understand the incident's possible scope, duration and nature
  • CSend a notification to the competent supervisory authority describing the incident.
  • DSend an email about the incident to all clients and ask them to change their passwords

How the community answered

(59 responses)
  • A
    14% (8)
  • B
    3% (2)
  • C
    76% (45)
  • D
    7% (4)

Explanation

You've hit your limit · resets 12:50am (America/New_York)

Topics

#data breach notification#ransomware#Article 33#incident response

Community Discussion

No community discussion yet for this question.

Full CIPP-E Practice