GDPR Data Management & Integration 2 — Questions and Answers
Question 1: When integrating a third-party CRM with an internal HR system, what GDPR obligation must be fulfilled before transferring employee personal data to the CRM vendor?
- Sign an NDA with the CRM vendor
- Execute a Data Processing Agreement (DPA) with the CRM vendor (Correct answer)
- Obtain explicit consent from all employees
- Notify the supervisory authority of the integration
Correct answer: Execute a Data Processing Agreement (DPA) with the CRM vendor
Article 28 requires a binding Data Processing Agreement before a controller engages a processor to handle personal data.
Question 2: A company runs an ETL pipeline that combines customer purchase data with demographic data purchased from a data broker. Which GDPR principle is most directly at risk?
- Storage limitation
- Purpose limitation (Correct answer)
- Data minimisation
- Integrity and confidentiality
Correct answer: Purpose limitation
Combining data for new profiling purposes that differ from the original collection purpose violates the purpose limitation principle under Article 5(1)(b).
Question 3: Under GDPR, when is a Data Protection Impact Assessment (DPIA) mandatory for a data integration project?
- Whenever two databases are joined, regardless of data type
- When processing is likely to result in high risk to individuals' rights and freedoms (Correct answer)
- Only when integrating data across EU member states
- Whenever the integrated dataset exceeds 10,000 records
Correct answer: When processing is likely to result in high risk to individuals' rights and freedoms
Article 35 requires a DPIA when processing is likely to result in a high risk; volume thresholds or cross-border aspects alone do not automatically trigger the obligation.
Question 4: A SaaS analytics platform stores aggregated user-behavior data. The company claims the data is anonymous. Under GDPR, the data would still be personal data if:
- The aggregated records contain more than 50 data fields
- The company holds any separate key that could re-identify individuals (Correct answer)
- The data is stored outside the EU
- The original collection did not have consent
Correct answer: The company holds any separate key that could re-identify individuals
Recital 26 states that data is personal if the controller or any other person can re-identify the individual using reasonably available means, including a retained key.
Question 5: An e-commerce company wants to share order data with a logistics partner in the US. The US partner has no EU adequacy decision. What is the recommended legal transfer mechanism?
- Legitimate interests under Article 6(1)(f)
- Standard Contractual Clauses (SCCs) approved by the European Commission (Correct answer)
- A bilateral NDA between both companies
- Binding Corporate Rules filed with the logistics partner's home state
Correct answer: Standard Contractual Clauses (SCCs) approved by the European Commission
Article 46 allows transfers using SCCs adopted by the Commission as an appropriate safeguard when no adequacy decision covers the destination country.
Question 6: A data lake ingests personal data from multiple source systems. Which data management practice best supports the GDPR right to erasure?
- Encrypting all data at rest
- Maintaining a data lineage map that tracks where each individual's data resides (Correct answer)
- Using columnar storage formats such as Parquet
- Partitioning data by ingestion date
Correct answer: Maintaining a data lineage map that tracks where each individual's data resides
A data lineage map enables the organisation to locate all copies of an individual's data across integrated systems, which is a prerequisite for complete erasure.
Question 7: When conducting a compatibility assessment for a new secondary use of personal data under Article 6(4), which factor is NOT listed in the GDPR?
- The link between the original and new purpose
- The nature of the personal data, especially whether special categories are involved
- The financial value the new purpose will generate for the controller (Correct answer)
- The possible consequences for data subjects
Correct answer: The financial value the new purpose will generate for the controller
Article 6(4) lists purpose link, data nature, consequences for subjects, and safeguards—commercial value of the new use is not a statutory factor.
When integrating a third-party CRM with an internal HR system, what GDPR obligation must be fulfilled before transferring employee personal data to the CRM vendor?