Certified Information Privacy Professional CIPPE · Free Practice Question Easy
Question 19
A doctor that allows the free access of his patients' health data on the web violates which provision of the GDPR?
-
A
Storage limitation
- B Security of processing
- C Data Minimisation
-
D
Accuracy
Reveal correct answer
Correct answer: B
Explanation
Medical records are sensitive data within the meaning of article Article 9 GDPR and should be treated with extra security e.g. encryption.
Data minimization would not apply as there is no evidence that the data is collecting excessive information in relation to the purpose for which the data is processed. There is not enough information to make the determination that inaccurate information was processed so the accuracy principle was not violated.
There is no evidence that the Dr. kept patient information in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed.
Discussion
Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.
