Question 41

Which of the following would MOST likely trigger the extraterritorial effect of the GDPR, as specified by Article 3?
  • Question 42

    When collecting personal data in a European Union (EU) member state, what must a company do if it collects personal data from a source other than the data subjects themselves?
  • Question 43

    SCENARIO
    Please use the following to answer the next question:
    Financially, it has been a very good year at ARRA Hotels: Their 21 hotels, located in Greece (5), Italy (15) and Spain (1), have registered their most profitable results ever. To celebrate this achievement, ARRA Hotels' Human Resources office, based in ARRA's main Italian establishment, has organized a team event for its 420 employees and their families at its hotel in Spain.
    Upon arrival at the hotel, each employee and family member is given an electronic wristband at the reception desk. The wristband serves a number of functions:
    . Allows access to the "party zone" of the hotel, and emits a buzz if the user approaches any unauthorized areas
    . Allows up to three free drinks for each person of legal age, and emits a buzz once this limit has been reached
    . Grants a unique ID number for participating in the games and contests that have been planned.
    Along with the wristband, each guest receives a QR code that leads to the online privacy notice describing the use of the wristband. The page also contains an unchecked consent checkbox. In the case of employee family members under the age of 16, consent must be given by a parent.
    Among the various activities planned for the event, ARRA Hotels' HR office has autonomously set up a photocall area, separate from the main event venue, where employees can come and have their pictures taken in traditional carnival costume.
    The photos will be posted on ARRA Hotels' main website for general marketing purposes.
    On the night of the event, an employee from one of ARRA's Greek hotels is displeased with the results of the photos in which he appears. He intends to file a complaint with the relevant supervisory authority in regard to the following:
    . The lack of any privacy notice in the separate photocall area
    The unlawful cross-border processing of his personal data
    . The unacceptable aesthetic outcome of his photos
    Why would consent NOT be considered an adequate legal basis for accessing the party zone?
  • Question 44

    When does the European Data Protection Board (EDPB) recommend reevaluating whether a transfer tool is effectively providing a level of personal data protection that is in compliance with the European Union (EU) level?
  • Question 45

    Which marketing-related activity is least likely to be covered by the provisions of Privacy and Electronic Communications Regulations (Directive 2002/58/EC)?