Certified Information Privacy Professional CIPPE · Free Practice Question Medium
Question 1
VideoCorp is a data controller that creates online video games. VideoCorp is concerned about the loss of market share as a result of emerging social platforms where users can easily download video games created by its competitors.
Video Corp identifies and teams up another video company Cool Apps to promote and market their video games on popular social media platforms.
Both VideoCorp and CoolApps procure services of a popular marketing firm, SocialCorp.
The Agreement between VideoCorp and CoolApps (Video game companies) and SocialCorp includes the following clauses:
1Video game companies instruct SocialCorp to process Company Personal Data
2SocialCorp shall in relation to the Video game companies’ Personal Data implement appropriate technical and organizational measures to ensure a level of security appropriate to that risk.
3SocialCorp shall not appoint (or disclose any Company Personal Data to) any Subprocessor unless required or authorized by VideoCorp
4SocialCorp shall promptly notify Video game Companies if it receives a request from a Data Subject under any Data Protection Law
5SocialCorp shall notify Video game Companies upon SocialCorp becoming aware of a Personal Data Breach affecting Company Personal Data
6Once SocialCorp completes the marketing campaign, it should delete all copies of the customer information provided by the Video game Companies
Both VideoCorp and CoolApps provide SocialCorp with access to their customer database to create the marketing campaign for its video games. CoolApps decides to use the customer database to identify eligible customers to test a new video game. CoolApps creates the list of eligible participants and emails them an invitation to test the game.
VideoCorp and CoolApps notice a week after SocialCorp's campaigns that sales of its video games have increased.
During that week, VideoCorp also receives a data deletion request from a VideoCorp customer that no longer wishes to receive any Video Corp marketing campaigns.
CoolApps receives a complaint from Customer Z who has received marketing communications from VideoCorp. Customer Z has never interacted or purchased video games from VideoCorp. Customer Z would like to know how VideoCorp obtained his email address.
A week after the marketing campaign ends, Social Corp decides to pseudonymize VideoCorp and CoolApps’s customer information for three months to conduct a research study on customers who purchase video games.
As a first step, what should VideoCorp and CoolApps have done before engaging SocialCorp?
-
A
Notified the Data Protection Authority
-
B
Notified their data protection officers
-
C
Drafted a Data Processing Agreement
-
D
Vet and check that Social Apps is qualified and suitable organization via a third party assessment
Reveal correct answer
Correct answer: D
Explanation
When entrusting a processor with processing activities, the controller should use only processors providing sufficient guarantees, in particular in terms of expert knowledge, reliability and resources, to implement technical and organisational measures which will meet the requirements of this Regulation, including for the security of processing.
This means that the data controller(s) should check and vet the processor by using a third party assessment or certification before a contract is created and afterwards.
Discussion
Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.
