CIPP-E · Question #263
CIPP-E Question #263: Real Exam Question with Answer & Explanation
The correct answer is D. More information about what students have been told and how the research will be used.. Before Anna determines whether Frank's performance database is permissible, she needs to know more information about the following aspects of the data processing: The purpose and legal basis of the data processing, which should be clearly defined and documented in a data protecti
Question
Options
- AMore information about Frank's data protection training.
- BMore information about the extent of the information loss.
- CMore information about the algorithm Frank used to mask student numbers.
- DMore information about what students have been told and how the research will be used.
Explanation
Before Anna determines whether Frank's performance database is permissible, she needs to know more information about the following aspects of the data processing: The purpose and legal basis of the data processing, which should be clearly defined and documented in a data protection impact assessment (DPIA) or a similar document. The nature and extent of the personal data involved, which should be limited to what is necessary for the purpose and not retained longer than necessary. The measures taken to ensure the security and confidentiality of the personal data, such as encryption, pseudonymization, access control, etc. The rights and interests of the data subjects, such as their right to access, rectify, erase or restrict their personal data, as well as their right to object or withdraw consent. The potential risks and consequences of the data processing for the rights and freedoms of the data subjects, such as identity theft, discrimination, reputational damage, etc. In this case, Anna needs to know more information about what students have been told and how the research will be used. This is The purpose of using student records for research purposes is not clear from Frank's description. He does not specify whether he has obtained consent from the students or their parents/guardians, or whether he has informed them about his research objectives and methods. The nature and extent of using student records for research purposes is not clear from Frank's description. He does not specify which student records he is using (e.g., by name or by reference number), how many records he is using (e.g., by cohort or by class), or how long he will keep them (e.g., until graduation or indefinitely). The measures taken to ensure the security and confidentiality of using student records for research purposes are not clear from Frank's description. He does not specify whether he has encrypted his program or his laptop before transferring it to his home device, whether he has backed up his program or his laptop before losing it on the train, or whether he has reported his lost laptop to his IT department. Therefore, Anna needs more information about these aspects before she can determine whether Frank's performance database is permissible under the GDPR.
Community Discussion
No community discussion yet for this question.