Certified Information Privacy Professional CIPPE · Free Practice Question Medium

Question 4

A customer requested a company to delete the personal data that the customer used to enroll in the company's ongoing Loyalty Program. Although the data controller confirmed the deletion of the customer data, the customer continued to receive unsolicited marketing emails related to the Loyalty Program from the company.

What is the likely reason the company violates the GDPR?

  • A

    The company continues to retain the customer's personal data

  • B

    The company confirmed the deletion of the customer's personal data

  • C

    The company continues to send marketing communications to the customer

  • D

    The company failed to suspend the Loyalty Program

Reveal correct answer

Correct answer: A

Explanation

The company failed to delete the customer's personal data thereby violating the GDPR. Under the GDPR, data subjects have the right to have their data deleted unless an exception under the GDPR applies.

Discussion

Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.

You must be logged in to post a comment.

Preparing For

Your Certification?

255+ certifications
Detailed explanations
Free PDF samples

Has All The Questions You Need