nerdexam
EXIN

PDPF · Question #53

After notifying the supervisory authority, what should be the first action the controller must take when it finds a security breach where unauthorized people have accessed personal data?

The correct answer is B. Analyze whether sensitive data has been accessed. It is necessary to check the extent of this personal data breach, what data has been accessed and what is the risk to his or her. Depending on this extension, in addition to notifying the supervisory authority, it will also be mandatory to notify the owners of the breached data.

Data protection breaches

Question

After notifying the supervisory authority, what should be the first action the controller must take when it finds a security breach where unauthorized people have accessed personal data?

Options

  • AContact the DPO for formal notification to the Supervisory Authority.
  • BAnalyze whether sensitive data has been accessed.
  • CRegister a Police Report at the cybercrime station.
  • DNotify data subjects that have been subject to a security breach.

How the community answered

(22 responses)
  • A
    9% (2)
  • B
    68% (15)
  • C
    5% (1)
  • D
    18% (4)

Explanation

It is necessary to check the extent of this personal data breach, what data has been accessed and what is the risk to his or her. Depending on this extension, in addition to notifying the supervisory authority, it will also be mandatory to notify the owners of the breached data.

Topics

#data breach response#controller obligations#breach management#supervisory authority notification

Community Discussion

No community discussion yet for this question.

Full PDPF Practice