exam questions

Exam CIPP-E All Questions

View all questions & answers for the CIPP-E exam

Exam CIPP-E topic 1 question 250 discussion

Actual exam question from IAPP's CIPP-E
Question #: 250
Topic #: 1
[All CIPP-E Questions]

If a company receives an anonymous email demanding ransom for the stolen personal data of its clients, what must the company do next, per GDPR requirements?

  • A. Notify the police and file a criminal complaint about the incident.
  • B. Start an investigation to understand the incident's possible scope, duration and nature.
  • C. Send a notification to the competent supervisory authority describing the incident.
  • D. Send an email about the incident to all clients and ask them to change their passwords.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
JacHa
4 days, 22 hours ago
Selected Answer: B
If the email only claims that personal data has been stolen it is answer B. If a breach indeed took place then, i may assume,the SA would already have been informed prior to the receiving of a ransom email. Answer C would apply but already a bit too late IMHO
upvoted 1 times
...
Ssourav
6 months ago
Selected Answer: C
C. Send a notification to the competent supervisory authority describing the incident.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago