Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CIPP-E All Questions

View all questions & answers for the CIPP-E exam

Exam CIPP-E topic 1 question 99 discussion

Actual exam question from IAPP's CIPP-E
Question #: 99
Topic #: 1
[All CIPP-E Questions]

Which of the following entities would most likely be exempt from complying with the GDPR?

  • A. A South American company that regularly collects European customers’ personal data.
  • B. A company that stores all customer data in Australia and is headquartered in a European Union (EU) member state.
  • C. A Chinese company that has opened a satellite office in a European Union (EU) member state to service European customers.
  • D. A North American company servicing customers in South Africa that uses a cloud storage system made by a European company.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
semilias
Highly Voted 1 year, 11 months ago
Selected Answer: D
article 2.2.a states: This Regulation does not apply to the processing of personal data: in the course of an activity which falls outside the scope of Union law; D is the option that does not process personal data from EU members or is done by controllers of processors related to EU
upvoted 6 times
...
Ssourav
Most Recent 3 months, 3 weeks ago
Selected Answer: D
D. A North American company servicing customers in South Africa that uses a cloud storage system made by a European company: The GDPR does not apply to this company because it is not processing personal data of individuals in the EU, nor does it have an establishment in the EU. The use of a cloud storage system made by a European company does not bring the North American company within the scope of the GDPR.
upvoted 1 times
...
SecretInvasion
1 year ago
Selected Answer: D
The best answer is clearly D. The problem with B is that it's unclear if that Australian company processes EU citizen data, but it probably has employees, and there must be a reason its HQ is in the EU. D is a clear-cut case.
upvoted 2 times
...
Ravi888
1 year, 6 months ago
D is the correct answer
upvoted 2 times
...
ZeroStatic
1 year, 7 months ago
Selected Answer: D
D is the correct answer, For clarification, see Example 7 in the 2018 Guidelines on Territorial Scope of the GDPR: https://edpb.europa.eu/sites/default/files/files/file1/edpb_guidelines_3_2018_territorial_scope_after_public_consultation_en_1.pdf Specifically: If a controller does not target EU market, and does not have establishments in the EU, the GDPR does not apply to it. Although the GDPR does apply to the processor, and they need to fulfill any regulations regarding its processing activities, this question is about the controller and *not* the processor.
upvoted 3 times
...
num
1 year, 8 months ago
Selected Answer: B
based on the information provided, option B is the most likely to be exempt from complying with the GDPR, as long as the company only stores customer data in Australia and is not established in the EU.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...