Question 31

What permissions are required for a marketer to send an email marketing message to a consumer in the EU?
  • Question 32

    Company X has entrusted the processing of their payroll data to Provider Y.
    Provider Y stores this encrypted data in its server. The IT department of Provider Y finds out that someone managed to hack into the system and take a copy of the data from its server. In this scenario, whom does Provider Y have the obligation to notify?
  • Question 33

    What must a data controller do in order to make personal data pseudonymous?
  • Question 34

    In which scenario is a Controller most likely required to undertake a Data Protection Impact Assessment?
  • Question 35

    Which of the following is the weakest lawful basis for processing employee personal data?