Certified Information Privacy Professional CIPPE · Free Practice Question Medium

Question 1

VideoCorp is a data controller that creates online video games. VideoCorp is concerned about the loss of market share as a result of emerging social platforms where users can easily download video games created by its competitors.

Video Corp identifies and teams up another video company Cool Apps to promote and market their video games on popular social media platforms.

Both VideoCorp and CoolApps procure services of a popular marketing firm, SocialCorp.

The Agreement between VideoCorp and CoolApps (Video game companies) and SocialCorp includes the following clauses:

1Video game companies instruct SocialCorp to process Company Personal Data

2SocialCorp shall in relation to the Video game companies’ Personal Data implement appropriate technical and organizational measures to ensure a level of security appropriate to that risk.

3SocialCorp shall not appoint (or disclose any Company Personal Data to) any Subprocessor unless required or authorized by VideoCorp

4SocialCorp shall promptly notify Video game Companies if it receives a request from a Data Subject under any Data Protection Law

5SocialCorp shall notify Video game Companies upon SocialCorp becoming aware of a Personal Data Breach affecting Company Personal Data

6Once SocialCorp completes the marketing campaign, it should delete all copies of the customer information provided by the Video game Companies

Both VideoCorp and CoolApps provide SocialCorp with access to their customer database to create the marketing campaign for its video games. CoolApps decides to use the customer database to identify eligible customers to test a new video game. CoolApps creates the list of eligible participants and emails them an invitation to test the game.

VideoCorp and CoolApps notice a week after SocialCorp's campaigns that sales of its video games have increased.

During that week, VideoCorp also receives a data deletion request from a VideoCorp customer that no longer wishes to receive any Video Corp marketing campaigns.

CoolApps receives a complaint from Customer Z who has received marketing communications from VideoCorp. Customer Z has never interacted or purchased video games from VideoCorp. Customer Z would like to know how VideoCorp obtained his email address.

A week after the marketing campaign ends, Social Corp decides to pseudonymize VideoCorp and CoolApps’s customer information for three months to conduct a research study on customers who purchase video games.

As a first step, what should VideoCorp and CoolApps have done before engaging SocialCorp?

  • A

    Notified the Data Protection Authority


  • B

    Notified their data protection officers


  • C

    Drafted a Data Processing Agreement


  • D

    Vet and check that Social Apps is qualified and suitable organization via a third party assessment

Reveal correct answer

Correct answer: D

Explanation

When entrusting a processor with processing activities, the controller should use only processors providing sufficient guarantees, in particular in terms of expert knowledge, reliability and resources, to implement technical and organisational measures which will meet the requirements of this Regulation, including for the security of processing.

This means that the data controller(s) should check and vet the processor by using a third party assessment or certification before a contract is created and afterwards.

Discussion

Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.

You must be logged in to post a comment.

Preparing For

Your Certification?

255+ certifications
Detailed explanations
Free PDF samples

Has All The Questions You Need