SCENARIO Please use the following to answer the next question: Zandelay Fashion ('Zandelay') is a successful international online clothing retailer that employs approximately 650 people at its headquarters based in Dublin, Ireland. Martin is their recently appointed data protection officer, who oversees the company's compliance with the General Data Protection Regulation (GDPR) and other privacy legislation. The company offers both male and female clothing lines across all age demographics, including children. In doing so, the company processes large amounts of information about such customers, including preferences and sensitive financial information such as credit card and bank account numbers. In an aggressive bid to build revenue growth, Jerry, the CEO, tells Martin that the company is launching a new mobile app and loyalty scheme that puts significant emphasis on profiling the company's customers by analyzing their purchases. Martin tells the CEO that: (a) the potential risks of such activities means that Zandelay needs to carry out a data protection impact assessment to assess this new venture and its privacy implications; and (b) where the results of this assessment indicate a high risk in the absence of appropriate protection measures. Zandelay may have to undertake a prior consultation with the Irish Data Protection Commissioner before implementing the app and loyalty scheme. Jerry tells Martin that he is not happy about the prospect of having to directly engage with a supervisory authority and having to disclose details of Zandelay's business plan and associated processing activities. What must Zandelay provide to the supervisory authority during the prior consultation?
A) An evaluation of the complexity of the intended processing.
B) An explanation of the purposes and means of the intended processing.
C) Records showing that customers have explicitly consented to the intended profiling activities.
D) Certificates that prove Martin's professional qualities and expert knowledge of data protection law.
Correct Answer:
Verified
Q97: What is the consequence if a processor
Q98: SCENARIO Please use the following to answer
Q99: Article 9 of the GDPR lists exceptions
Q100: What is an important difference between the
Q101: Which sentence BEST summarizes the concepts of
Q103: SCENARIO Please use the following to answer
Q104: Which of the following does NOT have
Q105: Read the following steps: Discover which employees
Q106: What obligation does a data controller or
Q107: What is true if an employee makes
Unlock this Answer For Free Now!
View this answer and more for free by performing one of the following actions
Scan the QR code to install the App and get 2 free unlocks
Unlock quizzes for free by uploading documents