exam questions

Exam CIPM All Questions

View all questions & answers for the CIPM exam

Exam CIPM topic 1 question 134 discussion

Actual exam question from IAPP's CIPM
Question #: 134
Topic #: 1
[All CIPM Questions]

Under the General Data Protection Regulation (GDPR), which of the following situations would LEAST likely require a controller to notify a data subject?

  • A. An encrypted USB key with sensitive personal data is stolen
  • B. A direct marketing email is sent with recipients visible in the ‘cc’ field
  • C. Personal data of a group of individuals is erroneously sent to the wrong mailing list
  • D. A hacker publishes usernames, phone numbers and purchase history online after a cyber-attack
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
0ef35ef
1 week ago
Selected Answer: B
Ultimately, A could absolutely be seen as less likely to require notification by the strict letter of the law if encryption is in place and there's minimal risk of decryption. But, if we're looking at risk factors in the broader sense, B could very well be a case where notification wouldn't always be required unless harm is foreseeable.
upvoted 1 times
...
alaaz
2 months ago
Selected Answer: B
i would go for B
upvoted 2 times
...
carlosbui
1 year, 2 months ago
should be A
upvoted 2 times
...
Ssourav
1 year, 4 months ago
Selected Answer: A
A. An encrypted USB key with sensitive personal data is stolen. Explanation: Under the GDPR, if personal data has been encrypted or pseudonymized and the keys to unlock the encryption or pseudonymization are not compromised, it can be considered safe from being accessed in an unauthorized manner. Thus, the loss or theft of an encrypted USB key with sensitive personal data would be considered a data breach, but it might not necessarily require notification to the data subjects, especially if there's a low risk of harm to the individuals due to the encryption.
upvoted 3 times
...
emily0922
1 year, 5 months ago
I suggest A, GDPR suggests if in the case there is reasonable protection like encryption it is likely that notification is not needed
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago