Certified Information Privacy Professional CIPPE · Free Practice Question Hard

Question 24

A university decided to allow students to sit for their examinations using videoconferencing. Students were required to identify themselves using an ID. After the exam, the recordings of the exams were available not only to the examinees but also to other people with access to the system. Besides, using a direct link, any outsider could access the exam recordings and the data of the examined students presented during the identification.

What should the university do to comply with the GDPR?

  • A

    Evaluate the risk to the rights or freedoms of the students and implement mitigation measures


  • B

    Notify the Data Protection Authority


  • C

    Notify the students


  • D

    All the above

Reveal correct answer

Correct answer: D

Explanation

Once a data breach occurs, the controller shall without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach to the supervisory authority competent in accordance with Article 55, unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons. Where the notification to the supervisory authority is not made within 72 hours, it shall be accompanied by reasons for the delay. When the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall communicate the personal data breach to the data subject without undue delay.

Under Article 33(1) GDPR and Article 34, the university has to notify both the supervisory authority, and the data subjects about the data protection breach.


Discussion

Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.

You must be logged in to post a comment.

Preparing For

Your Certification?

255+ certifications
Detailed explanations
Free PDF samples

Has All The Questions You Need