Which of the alternatives describes one of the Supervisory Authority's responsibilities?
According to the General Data Protection Regulation (GDPR), which category of personal data is considered to be sensitive data?
The illegal collection, storage, modification, disclosure or dissemination of personal data is an offense under European law.
What kind of offense is this?
Personal data can be transferred outside of the EEA. According to the GDPR, which transfers outside the EEA are always lawful?
One of the objectives of a data protection impact assessment (DPIA) is to strengthen the confidence of customers or citizens in the way personal data is processed and privacy is respected. How can a DPIA strengthen the confidence?
A processor is instructed to report on customers who bought a product both last month and at least once in the three months before that. Unfortunately, the processor makes a mistake and uses personal data collected by another controller for a different purpose.
The mistake is found before the report is created, and nobody has access to personal date he or she should not have had access to.
How should the processor act on this situation and what should the controller do, if anything?
What year did the General Data Protection Regulation (GDPR) come into force?