nerdexam
EXIN

PDPF · Question #114

A person who works for a union took home a draft newsletter to finish it. The thumb drive containing the draft and contact list has been lost. To whom, among others, this data breach should be…

The correct answer is A. An assessment of the need and proportionality of treatment operations in relation to the. This is sensitive data, so the loss must be reported to both the responsible authority and the data Which of these should appear in a Data Protection Impact Assessment (DPIA) according to the General Data Protection Regulation (GDPR)? In its Article 35 the GDPR legislates on…

Data protection breaches

Question

A person who works for a union took home a draft newsletter to finish it. The thumb drive containing the draft and contact list has been lost. To whom, among others, this data breach should be reported?

Options

  • AAn assessment of the need and proportionality of treatment operations in relation to the
  • BData Protection Officer (DPO) contact and responsibilities.
  • CAn inventory and the flow of personal data within the organization.
  • DA survey of other laws that must be taken into account in addition to the GDPR.

How the community answered

(39 responses)
  • A
    79% (31)
  • B
    3% (1)
  • C
    13% (5)
  • D
    5% (2)

Explanation

This is sensitive data, so the loss must be reported to both the responsible authority and the data Which of these should appear in a Data Protection Impact Assessment (DPIA) according to the General Data Protection Regulation (GDPR)? In its Article 35 the GDPR legislates on the Impact assessment on data protection. The assessment shall contain at least: a systematic description of the envisaged processing operations and the purposes of the processing, including, where applicable, the legitimate interest pursued by the controller; an assessment of the necessity and proportionality of the processing operations in relation to the purposes; an assessment of the risks to the rights and freedoms of data subjects referred to in paragraph 1; and the measures envisaged to address the risks, including safeguards, security measures and mechanisms to ensure the protection of personal data and to demonstrate compliance with this Regulation taking into account the rights and legitimate interests of data subjects and other persons

Topics

#data breach#special categories#union membership#breach reporting

Community Discussion

No community discussion yet for this question.

Full PDPF Practice