Certified Information Privacy Professional CIPPE · Free Practice Question Medium

Question 22

VideoCorp is a data controller that creates online video games. VideoCorp is concerned about the loss of market share as a result of emerging social platforms where users can easily download video games created by its competitors.

VideoCorp identifies and teams up another video company CoolApps to promote and market their video games on popular social media platforms.

Both VideoCorp and CoolApps procure services of a popular marketing firm, Social Corp.

The Agreement between the Video game companies and SocialCorp includes the following clauses:

1Video game companies instruct SocialCorp to process Company Personal Data

2SocialCorp shall in relation to the Video game companies’ Personal Data implement appropriate technical and organizational measures to ensure a level of security appropriate to that risk.

3SocialCorp shall not appoint (or disclose any Company Personal Data to) any Sub-processor unless required or authorized by VideoCorp

4SocialCorp shall promptly notify Video game Companies if it receives a request from a Data Subject under any Data Protection Law

5SocialCorp shall notify Video game Companies upon SocialCorp becoming aware of a Personal Data Breach affecting Company Personal Data

6Once SocialCorp completes the marketing campaign, it should delete all copies of the customer information provided by the Video game Companies

Both VideoCorp and CoolApps provide SocialCorp with access to their customer database to create the marketing campaign for its video games. CoolApps decides to use the customer database to identify eligible customers to test a new video game. CoolApps creates the list of eligible participants and emails them an invitation to test the game.

VideoCorp and CoolApps notice a week after SocialCorp's campaigns that sales of its video games have increased.

During that week,VideoCorp also receives a data deletion request from a VideoCorp customer that no longer wishes to receive any Video Corp marketing campaigns.

CoolApps receives a complaint from Customer Z who has received marketing communications from VideoCorp. Customer Z has never interacted or purchased video games from VideoCorp. Customer Z would like to know how VideoCorp obtained his email address.

A week after the marketing campaign ends, Social Corp decides to pseudonymize VideoCorp and CoolApps’s customer information for three months to conduct a research study on customers who purchase video games.

What should VideoCorp do if it receives a data deletion request from a VideoCorp customer?

  • A

    VideoCorp should respond to the data subject within 72 hours


  • B

    Notify Cool Apps in 30 days


  • C

    Respond to the data subject in 60 days


  • D

    Respond to the data subject without undue delay or 30 days within receipt of the request

Reveal correct answer

Correct answer: D

Explanation

The controller shall provide information on action taken on a request under Articles 15 to 22 to the data subject without undue delay and in any event within one month of receipt of the request.

The data subject shall have the right to obtain from the controller the erasure of personal data concerning him or her without undue delay and the controller shall have the obligation to erase personal data without undue delay where one of the following grounds applies:

1the personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed

2the data subject withdraws consent on which the processing is based according to point (a) of Article 6(1), or point (a) of Article 9(2), and where there is no other legal ground for the processing

3the data subject objects to the processing pursuant to Article 21(1) and there are no overriding legitimate grounds for the processing, or the data subject objects to the processing pursuant to Article 21(2)

4the personal data have been unlawfully processed

5the personal data have to be erased for compliance with a legal obligation in Union or Member State law to which the controller is subject

6the personal data have been collected in relation to the offer of information society services referred to in Article 8(1).

Discussion

Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.

You must be logged in to post a comment.

Preparing For

Your Certification?

255+ certifications
Detailed explanations
Free PDF samples

Has All The Questions You Need