nerdexam
EXIN

PDPF · Question #71

The controller responsible for the UK Child Sexual Abuse Investigation body reported a data breach to the supervisory authority in the UK on 28 February 2019. People who had registered their…

The correct answer is A. This data breach should only be reported to the Data Protection Authority. Here we have a very common catch in EXIN exams. In this matter, the personal data that was breached included the email addresses. Although the group is a subject considered sensitive by the GDPR, only other participants who had registered took notice. As it does not present a…

Data protection breaches

Question

The controller responsible for the UK Child Sexual Abuse Investigation body reported a data breach to the supervisory authority in the UK on 28 February 2019. People who had registered their interest in participating in forums and debates for victims of child sexual abuse received an email that contained the email addresses of everyone else who had also registered. Which category does this data breach fit into?

Options

  • AThis data breach should only be reported to the Data Protection Authority.
  • BThis data breach should only be reported to data subjects.
  • CIt is not necessary to notify the Supervisory Authority, as this data breach presents minimal risks to
  • DThis data breach must be reported to the Data Protection Authority and the data subjects.

How the community answered

(58 responses)
  • A
    84% (49)
  • B
    9% (5)
  • C
    5% (3)
  • D
    2% (1)

Explanation

Here we have a very common catch in EXIN exams. In this matter, the personal data that was breached included the email addresses. Although the group is a subject considered sensitive by the GDPR, only other participants who had registered took notice. As it does not present a high risk to data subjects, there is no need to notify the data subject as well. Only the Supervisory Authority is enough. However, after notifying the Supervisory Authority, it may decide that the data subject should also be notified, but for that matter this is not considered. Article 33 of the GDPR legislates on the topic "Notification of a personal data breach to the 1. In the case of a personal data breach, the controller shall without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach to the supervisory authority competent in accordance with Article 55, unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons. Where the notification to the supervisory authority is not made within 72 hours, it shall be accompanied by reasons for the delay. The deadline for notification of data breaches to the Supervisory Authority is generally charged in the EXIN exam. This period is 72 hours.

Topics

#data breach notification#supervisory authority#breach categorization#risk assessment

Community Discussion

No community discussion yet for this question.

Full PDPF Practice