Which of the following information must be provided by the data controller when complying with GDPR ''right to be informed'' requirements?
Correct : C
Start a Discussions
When a data breach incident has occurred. the first priority is to determine?
Start a Discussions
Which of the following is NOT a main technical data control area?
Start a Discussions
Integrating privacy requirements into functional areas across the organization happens at which stage of the privacy operational life cycle?
Correct : B
Integrating privacy requirements into functional areas across the organization happens at the ''protect'' stage of the privacy operational life cycle. This stage involves implementing privacy policies, procedures, and controls to ensure that personal data is processed in a lawful, fair, and transparent manner. The other stages of the privacy operational life cycle are ''assess'', ''align'', ''respond'', and ''sustain''.Reference:CIPM Body of Knowledge, Domain III: Privacy Program Operational Life Cycle, Section B: Protect.
Start a Discussions
Under the General Data Protection Regulation (GDPR), what must be included in a written agreement between the controller and processor in relation to processing conducted on the controller's behalf?
Correct : D
Under the GDPR, a written agreement between the controller and processor in relation to processing conducted on the controller's behalf must include an obligation on the processor to assist the controller in complying with the controller's obligations to notify the supervisory authority about personal data breaches. This is one of the requirements under Article 28(3)(f) of the GDPR, which specifies the minimum content of such an agreement. The other options are not required by the GDPR, although they may be agreed upon by the parties as additional terms.Reference:GDPR, Article 28(3)(f).
Start a Discussions