Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CIPP-E All Questions

View all questions & answers for the CIPP-E exam

Exam CIPP-E topic 1 question 214 discussion

Actual exam question from IAPP's CIPP-E
Question #: 214
Topic #: 1
[All CIPP-E Questions]

SCENARIO -

Please use the following to answer the next question:

CreditPlaya, SA is an established Spanish online insurance company whose exclusive activity is providing health insurance for legal residents of Spain, regardless of their nationality.

CreditPlaya autonomously manages its own website, through which a potential customer, engaging in a free pre-contractual activity, enters his or her full name, e-mail address, tax identification number (to verify residence in Spain), age, profession, and the full names of any other adult members of his or her family.

With this data, CreditPlaya immediately sends an email granting or denying eligibility for a health insurance policy. In the case of eligibility, the email also contains the eventual cost of the policy and two PDF documents – one with the contractual Terms and Conditions, and the other with the privacy notice as required by Article 13 of the GDPR.

The CreditPlaya Information Tracking System (ITS) is very efficient, with a low rate of unpaid insurance policies. The ITS is automatically fed by the information provided by every applicant, whose data is then used to refine insurance policy rates.

To ensure their back-up procedures, in January 2021 CreditPlaya started sending weekly copies of the whole database with all the applicants' personal data to an independent company in Uruguay. The information was sent through state-of-the-art encrypting tools, but once in Uruguay was stored without any encryption method.

In March 2022, the entire data base stored on the Uruguay's company servers was encrypted by malicious ransomware. There was no evidence that the data was accessed by unauthorized persons, much less altered or exfiltrated. Despite the incident, CreditPlaya found that they could rely on the locally based Spanish back-up information and carry on its activity without interrupting its operations. The incident caused the termination of the professional relationship between the two companies.


The content of the email that CreditPlaya sends does not comply with GDPR requirements because it lacks what?

  • A. The list of information with regard to personal data that were not obtained from the data subject, according to Article 14.
  • B. The list of the processors and subprocessors involved in the processing, as required by Article 28.
  • C. The list of processing activities as set out in the records of processing activities, according to Article 30.
  • D. The list of technical and organizational measures that will be implemented, according to Article 32.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Ssourav
3 months, 3 weeks ago
Selected Answer: A
A. The list of information with regard to personal data that were not obtained from the data subject, according to Article 14. Rationale: The GDPR mandates that when personal data is obtained not directly from the data subject but from other sources, the controller must provide the data subject with certain information. This includes details about the data's source, the categories of personal data, the purpose of processing, and the recipients of the data, among other things (Article 14). Since the email from CreditPlaya includes personal data that might not have been directly provided by the data subject, it should comply with these notification requirements.
upvoted 2 times
7f814c6
3 months, 2 weeks ago
Good point, the insurance rates calculated by the ITS are a form of derived data, which might not have been directly obtained from the data subjects themselves but rather generated through processing of the provided data.
upvoted 1 times
...
...
bb9dcb9
8 months, 1 week ago
Selected Answer: B
The closet is B
upvoted 3 times
7f814c6
4 months ago
I think their notice is missing the information about Article 13(1)(f), they have to notify the processor is located in Uruguay, since the fact of international transfer should be recognized. At the same time, the notification must also contain information about the adequacy decision for Uruguay.
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...