nerdexam
IAPP

CIPP-E · Question #49

An unforeseen power outage results in company Z's lack of access to customer data for six hours. According to article 32 of the GDPR, this is considered a breach. Based on the WP 29's February, 2018…

The correct answer is B. Document the loss of availability to demonstrate accountability. According to Article 32 of the GDPR, the controller and the processor must implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk of the processing, including the ability to restore the availability and access to…

Compliance with European Data Protection Law

Question

An unforeseen power outage results in company Z's lack of access to customer data for six hours. According to article 32 of the GDPR, this is considered a breach. Based on the WP 29's February, 2018 guidance, company Z should do which of the following?

Options

  • ANotify affected individuals that their data was unavailable for a period of time.
  • BDocument the loss of availability to demonstrate accountability
  • CNotify the supervisory authority about the loss of availability
  • DConduct a thorough audit of all security systems

How the community answered

(37 responses)
  • A
    14% (5)
  • B
    57% (21)
  • C
    5% (2)
  • D
    24% (9)

Explanation

According to Article 32 of the GDPR, the controller and the processor must implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk of the processing, including the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident. A personal data breach is defined as a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed. Therefore, a power outage that results in the loss of availability of customer data for six hours is considered a personal data breach under the GDPR. Based on the WP 29's February, 2018 guidance, which was endorsed by the European Data Protection Board, company Z should document the loss of availability to demonstrate accountability. The guidance states that controllers must document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken, regardless of whether the breach needs to be notified to the supervisory authority or the data subjects. This documentation must enable the supervisory authority to verify compliance with the GDPR and must be made available to the supervisory authority on request.

Topics

#availability breach#Article 32#accountability#WP29 guidance

Community Discussion

No community discussion yet for this question.

Full CIPP-E Practice