exam questions

Exam CIPP-E All Questions

View all questions & answers for the CIPP-E exam

Exam CIPP-E topic 1 question 292 discussion

Actual exam question from IAPP's CIPP-E
Question #: 292
Topic #: 1
[All CIPP-E Questions]

SCENARIO -

Please use the following to answer the next question:

It has been a tough season for the Spanish Handball League, with acts of violence and racism having increased exponentially during their last few matches.

In order to address this situation, the Spanish Minister of Sports, in conjunction with the National Handball League Association, issued an Administrative Order (the "Act") obliging all the professional clubs to install a fingerprint-reading system for accessing some areas of the sports halls, primarily the ones directly behind the goalkeepers. The rest of the areas would retain the current access system, which allows any spectators access as long as they hold valid tickets.

The Act named a selected hardware and software provider, New Digital Finger, Ltd., for creation of the new fingerprint system. Additionally, it stipulated that any of the professional clubs that failed to install this system within a two-year period would face fines under the Act.

The Murla HB Club was the first to install the new system, renting the New Digital Finger hardware and software. Immediately afterwards, the Murla HB Club automatically renewed current supporters’ subscriptions, while introducing a new contractual clause requiring supporters to access specific areas of the hall through the new fingerprint reading system installed at the gates.

After the first match hosted by the Murla HB Club, a local supporter submitted a complaint to the club and to the Spanish Data Protection Authority (the AEPD), claiming that the new access system violates EU data protection laws. Having been notified by the AEPD of the upcoming investigation regarding this complaint, the Murla HB Club immediately carried out a Data Protection Impact Assessment (DPIA), the conclusions of which stated that the new access system did not pose any high risks to data subjects' privacy rights.

According to Article 83 of the GDPR, what should the AEPD take into account when determining a possible fine?

  • A. That the complainant had adhered to a binding contractual clause.
  • B. That the Murla HB Club promptly obeyed the Administrative Order (the Act).
  • C. That the Murla HB Club immediately carried out a DPIA after the AEPD notification.
  • D. That the number of affected data subjects is limited to the ones accessing a specific area.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Vijay7777
3 days, 3 hours ago
Selected Answer: D
Correct answer: D – aligns with Art. 83(2)(a): number of data subjects matters in fine calculation. GDPR fines consider: gravity, nature, duration, intent, number of affected subjects, degree of cooperation, prior history, etc. Prompt DPIA post-incident (C) ≠ compliance. Obeying national law (B) ≠ valid defense if GDPR is violated. Binding contracts (A) ≠ valid waiver of GDPR rights.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...