Certified Information Privacy Professional CIPPE · Free Practice Question Medium
Question 23
Great Work LLC is a regional EU company with 200,000 employees.
Great Work LLC recently implemented a new software, the Internet access registration system, to trace the history of the websites visited by the employees and the browsing time for each site. Data that is collected includes the userID, date, time, PC used, and website visited. The data that is collected is stored for 6 months to a year. The purpose of the system is to prevent employees from visiting non-work related sites and protect the company network.
The Internet access registration system was selected on the assumption that it would not present specific risks to employees. New employees are provided general information about monitoring of the internet browsers in company documents such as the Code of Conduct and the trade union agreement. Employees are not informed to what extent they are allowed to use the network for personal reasons and in which cases monitoring can be triggered.
Great Work LLC Managers are also allowed to submit requests to the network administrator to access the internet browsing reports of their staff.
Recently, Dave who started working at Great Work is surprised to receive a notice of initiation of disciplinary proceedings from the Company HR manager for using a significant time at work to view social media websites not related to his work. He decides to submit a complaint to the Supervisory Authority.
Should Great LLC have allowed managers to use the data collected for disciplinary purposes?
- A No, it was incompatible with the purpose of securing the company network
- B Yes, to ensure workers are productive
-
C
Yes, provided the managers had a suspicion that workers were spending most of their time browsing the internet
- D No, unless the employees were aware they could be disciplined for visiting non-work related sites
Reveal correct answer
Correct answer: A
Explanation
Great Work LLC without adequately informing the employees, allowed processing operations that were unnecessary and disproportionate to the purpose of protecting and securing the internal network, by carrying out a preventive and generalised collection of data relating to connections to websites visited by individual employees and using that information for disciplinary purposes.
Under Article 5 of the GDPR, personal data shall be collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes. The use of the information for disciplinary purposes was incompatible with the purpose of protecting and securing the internal network.
Discussion
Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.
