PDPF · Question #59
A company CEO travels to a meeting in another city. He takes a notebook with information about the company's new projects and acquisitions, which will be the subject of discussion at this meeting…
The correct answer is A. A security incident. The purpose of GDPR is to protect personal data. In the case of this issue there was no loss of personal data, so it is not a data breach. A data breach is whenever something happens that has not been planned with the personal data, be it improper processing, improper sharing…
Question
A company CEO travels to a meeting in another city. He takes a notebook with information about the company’s new projects and acquisitions, which will be the subject of discussion at this meeting. These are the only data stored on the notebook. The notebook accidentally falls into the hotel’s pool and all data is lost. What happened, considering the General Data Protection Regulation (GDPR)?
Options
- AA security incident
- BA vulnerability
- CA data breach
- DA security risk
How the community answered
(17 responses)- A82% (14)
- B6% (1)
- D12% (2)
Explanation
The purpose of GDPR is to protect personal data. In the case of this issue there was no loss of personal data, so it is not a data breach. A data breach is whenever something happens that has not been planned with the personal data, be it improper processing, improper sharing, loss of data, deletion, etc. That is, personal data must be used for a specific purpose, respecting the life cycle (from collection to exclusion), any situation that escapes this cycle must be reported as a data breach.
Topics
Community Discussion
No community discussion yet for this question.