IAPP
CIPP-E · Question #234
It a company receives an anonymous email demanding ransom for the stolen personal data of its clients, what must the company do next, per GDPR requirements'3
The correct answer is C. Send a notification to the competent supervisory authority describing the incident. You've hit your limit · resets 12:50am (America/New_York)
Compliance with European Data Protection Law
Question
It a company receives an anonymous email demanding ransom for the stolen personal data of its clients, what must the company do next, per GDPR requirements'3
Options
- ANotify the police and Tile a criminal complaint about the incident
- BStart an investigation to understand the incident's possible scope, duration and nature
- CSend a notification to the competent supervisory authority describing the incident.
- DSend an email about the incident to all clients and ask them to change their passwords
How the community answered
(59 responses)- A14% (8)
- B3% (2)
- C76% (45)
- D7% (4)
Explanation
You've hit your limit · resets 12:50am (America/New_York)
Topics
#data breach notification#ransomware#Article 33#incident response
Community Discussion
No community discussion yet for this question.