List of questions
Related questions
Question 72 - CIPP-E discussion
An employee of company ABCD has just noticed a memory stick containing records of client data, including their names, addresses and full contact details has disappeared. The data on the stick is unencrypted and in clear text. It is uncertain what has happened to the stick at this stage, but it likely was lost during the travel of an employee. What should the company do?
Notify as soon as possible the data protection supervisory authority that a data breach may have taken place.
Launch an investigation and if nothing is found within one month, notify the data protection supervisory authority.
Invoke the "disproportionate effort" exception under Article 33 to postpone notifying data subjects until more information can be gathered.
Immediately notify all the customers of the company that their information has been accessed by an unauthorized person.
0 comments
Leave a comment first