Scenario: 2
Soyled is a retail company that sells a wide range of electronic products from top European brands. It primarily sells its products in its online platforms (which include customer reviews and ratings), despite using physical stores since 2015. Soyled's website and mobile app are used by millions of customers. Soyled has employed various solutions to create a customer-focused ecosystem and facilitate growth. Soyled uses customer relationship management (CRM) software to analyze user data and administer the interaction with customers. The software allows the company to store customer information, identify sales opportunities, and manage marketing campaigns. It automatically obtains information about each user's IP address and web browser cookies. Soyled also uses the software to collect behavioral data, such as users' repeated actions and mouse movement information. Customers must create an account to buy from Soyled's online platforms. To do so, they fill out a standard sign-up form of three mandatory boxes (name, surname, email address) and a non-mandatory one (phone number). When the user clicks the email address box, a pop-up message appears as follows: ''Soyled needs your email address to grant you access to your account and contact you about any changes related to your account and our website. For further information, please read our privacy policy.' When the user clicks the phone number box, the following message appears: ''Soyled may use your phone number to provide text updates on the order status. The phone number may also be used by the shipping courier." Once the personal data is provided, customers create a username and password, which are used to access Soyled's website or app. When customers want to make a purchase, they are also required to provide their bank account details. When the user finally creates the account, the following message appears: ''Soyled collects only the personal data it needs for the following purposes: processing orders, managing accounts, and personalizing customers' experience. The collected data is shared with our network and used for marketing purposes." Soyled uses personal data to promote sales and its brand. If a user decides to close the account, the personal data is still used for marketing purposes only. Last month, the company received an email from John, a customer, claiming that his personal data was being used for purposes other than those specified by the company. According to the email, Soyled was using the data for direct marketing purposes. John requested details on how his personal data was collected, stored, and processed. Based on this scenario, answer the following Questio n:
Questio n:
The GDPR indicates that the processing of personal data should be based on a legal contract with the data subject. Based on scenario 6, has Soyled fulfilled this requirement?
Answer : C
Under Article 6(1) of GDPR, processing personal data must have a lawful basis, such as consent, contract, legal obligation, or legitimate interest. Additionally, under Article 13, controllers must inform users before collecting their data.
Soyled failed to disclose that personal data would be shared with the network before collection, which violates GDPR transparency requirements. Option C is correct. Option A is incorrect because informing about email collection does not mean lawful processing. Option B is incorrect because the information was not disclosed at the right time. Option D is incorrect because explicit consent is not necessarily required if another lawful basis applies.
GDPR Article 6(1) (Lawfulness of processing)
GDPR Article 13(1) (Transparency in data processing)
Questio n:
Under GDPR, the controller must demonstrate that data subjects have consented to the processing of their personal data, and the consent must be freely given.
What is the role of the DPO in ensuring compliance with this requirement?
Answer : B
Under Article 7(1) of GDPR, controllers must be able to demonstrate that the data subject has given consent. The DPO advises on ensuring these procedures are in place but does not collect or approve consent directly.
Option B is correct because the DPO must verify that consent records exist and meet GDPR standards.
Option A is incorrect because informing data subjects about withdrawal rights is the controller's duty, not the DPO's.
Option C is incorrect because the DPO does not personally maintain consent logs.
Option D is incorrect because DPOs do not approve legal bases for processing---this is the controller's responsibility.
GDPR Article 7(1) (Controller must demonstrate valid consent)
GDPR Article 39(1)(b) (DPO ensures compliance with data protection obligations)
Questio n:
What can be included in a DPIA?
Answer : D
Under Article 35(7) of GDPR, a DPIA must include:
A description of processing activities and their purpose.
An assessment of necessity and proportionality.
An assessment of risks to individuals.
Planned measures to address risks.
Option D is correct because all these elements are essential for a DPIA.
Option A is correct because documenting cross-border data transfers is required under GDPR Article 35(7)(d).
Option B is correct because security measures must be described to mitigate risks.
Option C is correct because assessing risks to individuals is the core function of a DPIA.
GDPR Article 35(7) (DPIA requirements)
Recital 90 (DPIA helps controllers manage processing risks)
Scenario:
A financial institution collects biometric data of its clients, such as face recognition, to support a payment authentication process that they recently developed. The institution ensures that data subjects provide explicit consent for the processing of their biometric data for this specific purpose.
Questio n:
Based on this scenario, should the DPO advise the organization to conduct a DPIA (Data Protection Impact Assessment)?
Answer : A
Under Article 35(3)(b) of GDPR, a DPIA is mandatory for processing that involves large-scale processing of special category data, including biometric data. Even if explicit consent is obtained, the risks associated with biometric processing require further evaluation.
Option A is correct because biometric data processing poses high risks to fundamental rights and freedoms, necessitating a DPIA.
Option B is incorrect because obtaining consent does not eliminate the requirement to conduct a DPIA.
Option C is incorrect because DPIAs are required for biometric processing regardless of scale if risks are present.
Option D is incorrect because storage duration is not a determining factor for DPIA requirements.
GDPR Article 35(3)(b) (DPIA requirement for special category data)
Recital 91 (Processing biometric data requires special safeguards)
Scenario: 2
Soyled is a retail company that sells a wide range of electronic products from top European brands. It primarily sells its products in its online platforms (which include customer reviews and ratings), despite using physical stores since 2015. Soyled's website and mobile app are used by millions of customers. Soyled has employed various solutions to create a customer-focused ecosystem and facilitate growth. Soyled uses customer relationship management (CRM) software to analyze user data and administer the interaction with customers. The software allows the company to store customer information, identify sales opportunities, and manage marketing campaigns. It automatically obtains information about each user's IP address and web browser cookies. Soyled also uses the software to collect behavioral data, such as users' repeated actions and mouse movement information. Customers must create an account to buy from Soyled's online platforms. To do so, they fill out a standard sign-up form of three mandatory boxes (name, surname, email address) and a non-mandatory one (phone number). When the user clicks the email address box, a pop-up message appears as follows: ''Soyled needs your email address to grant you access to your account and contact you about any changes related to your account and our website. For further information, please read our privacy policy.' When the user clicks the phone number box, the following message appears: ''Soyled may use your phone number to provide text updates on the order status. The phone number may also be used by the shipping courier." Once the personal data is provided, customers create a username and password, which are used to access Soyled's website or app. When customers want to make a purchase, they are also required to provide their bank account details. When the user finally creates the account, the following message appears: ''Soyled collects only the personal data it needs for the following purposes: processing orders, managing accounts, and personalizing customers' experience. The collected data is shared with our network and used for marketing purposes." Soyled uses personal data to promote sales and its brand. If a user decides to close the account, the personal data is still used for marketing purposes only. Last month, the company received an email from John, a customer, claiming that his personal data was being used for purposes other than those specified by the company. According to the email, Soyled was using the data for direct marketing purposes. John requested details on how his personal data was collected, stored, and processed. Based on this scenario, answer the following Questio n:
Questio n:
When completing the sign-up form, the user gets a notification about the purpose for which Soyled collects their email address. Is Soyled required by the GDPR to do so?
Answer : A
Under Article 13 of GDPR, controllers must inform data subjects at the time of data collection about the purpose of processing their personal data. This ensures transparency and accountability.
Soyled provides a pop-up message explaining why the email is collected, which aligns with GDPR's transparency principles. Option A is correct. Option B is incorrect because GDPR requires notification at collection, not upon request. Option C is incorrect as GDPR mandates disclosure of purpose, not just storage and processing methods. Option D is misleading because the purpose must be disclosed regardless of communication intent.
GDPR Article 13(1)(c) (Obligation to inform data subjects about processing purposes)
Recital 60 (Transparency and accountability in data collection)
Scenario 6:
Bus Spot is one of the largest bus operators in Spain. The company operates in local transport and bus rental since 2009. The success of Bus Spot can be attributed to the digitization of the bus ticketing system, through which clients can easily book tickets and stay up to date on any changes to their arrival or departure time. In recent years, due to the large number of passengers transported daily. Bus Spot has dealt with different incidents including vandalism, assaults on staff, and fraudulent injury claims. Considering the severity of these incidents, the need for having strong security measures had become crucial. Last month, the company decided to install a CCTV system across its network of buses. This security measure was taken to monitor the behavior of the company's employees and passengers, enabling crime prevention and ensuring safety and security. Following this decision, Bus Spot initiated a data protection impact assessment (DPIA). The outcome of each step of the DPIA was documented as follows: Step 1: In all 150 buses, two CCTV cameras will be installed. Only individuals authorized by Bus Spot will have access to the information generated by the CCTV system. CCTV cameras capture images only when the Bus Spot's buses are being used. The CCTV cameras will record images and sound. The information is transmitted to a video recorder and stored for 20 days. In case of incidents, CCTV recordings may be stored for more than 40 days and disclosed to a law enforcement body. Data collected through the CCTV system will be processed bv another organization. The purpose of processing this tvoe of information is to increase the security and safety of individuals and prevent criminal activity. Step 2: All employees of Bus Spot were informed for the installation of a CCTV system. As the data controller, Bus Spot will have the ultimate responsibility to conduct the DPI
Answer : A, A
Under Article 35(7)(b) of GDPR, a DPIA must include an assessment of the necessity and proportionality of processing. This ensures that data processing is lawful, limited, and justified. Bus Spot missed this step, which is essential for verifying the lawful basis for processing CCTV data.
Option A is correct because the necessity and proportionality assessment was required but not completed.
Option B is incorrect because Bus Spot documented data processing activities in the DPIA.
Option C is incorrect because not aligning with GDPR guidelines does not automatically invalidate a DPIA.
Option D is incorrect because prior approval from a supervisory authority is only required if high-risk processing is detected without sufficient mitigation measures (Article 36).
GDPR Article 35(7)(b) (Necessity and proportionality in DPIAs)
Recital 90 (Assessing necessity in a DPIA)
Which statement below regarding the difference between anonymization and pseudonymization is correct?
Answer : B
According to GDPR Recital 26, anonymization permanently removes any possibility of re-identification, making it irreversible. Pseudonymization, as defined in Article 4(5), is reversible if the correct key or additional information is available. Pseudonymization still qualifies as personal data under GDPR, whereas anonymized data falls outside the scope of GDPR.