GDPR Troubleshooting & Problem Resolution 2 — Questions and Answers
Question 1: A data subject submits a Subject Access Request (SAR) but fails to specify which processing activities they are inquiring about. What is the controller's correct first step?
- Reject the SAR as incomplete
- Request clarification from the data subject before the clock starts
- Respond within one month covering all personal data held (Correct answer)
- Transfer the request to the DPO for legal review
Correct answer: Respond within one month covering all personal data held
Under GDPR Article 12(3), the one-month response clock begins at receipt of the request; controllers must respond to all personal data held even if the request is vague.
Question 2: An employee inadvertently emails a spreadsheet containing 500 customers' health data to a wrong recipient outside the organization. How should this be classified?
- A minor human error requiring only internal logging
- A personal data breach requiring assessment for supervisory authority notification (Correct answer)
- An incident requiring immediate erasure without further action
- A processor breach that is solely the recipient's responsibility
Correct answer: A personal data breach requiring assessment for supervisory authority notification
Unauthorized disclosure of special-category data constitutes a personal data breach under Article 4(12), triggering the 72-hour notification assessment under Article 33.
Question 3: A controller discovers that its cookie consent banner never recorded opt-ins due to a technical bug running for six months. What is the primary compliance failure?
- Violation of Article 30 record-keeping obligations
- Lack of valid consent making all consent-based processing unlawful (Correct answer)
- Failure to appoint a DPO for website management
- Breach of data minimisation under Article 5(1)(c)
Correct answer: Lack of valid consent making all consent-based processing unlawful
Without a recorded opt-in, consent under Article 7 cannot be demonstrated, rendering any processing that relied on it unlawful from the start.
Question 4: A third-party processor notifies your organization of a breach affecting your data 96 hours after discovery. Which obligation has been violated?
- The processor's duty to notify the controller 'without undue delay' under Article 33(2) (Correct answer)
- The controller's 72-hour window to notify the supervisory authority
- The data subject's right to be informed within 24 hours
- The DPO's obligation to record the breach in the Article 30 register
Correct answer: The processor's duty to notify the controller 'without undue delay' under Article 33(2)
Article 33(2) requires processors to notify the controller without undue delay after becoming aware of a breach, independent of the controller's own 72-hour clock.
Question 5: During a DPIA, the project team identifies a residual high risk that cannot be mitigated to an acceptable level. What must the controller do?
- Proceed with processing and document the risk in the Article 30 register
- Consult the supervisory authority prior to commencing processing under Article 36 (Correct answer)
- Transfer the risk to the processor via a data processing agreement
- Appoint an external auditor to approve the project
Correct answer: Consult the supervisory authority prior to commencing processing under Article 36
Article 36(1) mandates prior consultation with the supervisory authority when a DPIA reveals a high residual risk that the controller cannot mitigate.
Question 6: A data subject requests erasure of their data. The controller holds the data under a legal obligation to retain records for seven years. What is the correct response?
- Erase the data immediately to honour the right
- Deny the erasure request citing the legal obligation and inform the data subject (Correct answer)
- Pseudonymise the data and consider this equivalent to erasure
- Transfer the data to a third country outside GDPR jurisdiction
Correct answer: Deny the erasure request citing the legal obligation and inform the data subject
Article 17(3)(b) exempts controllers from erasure obligations when processing is necessary for compliance with a legal obligation, and they must inform the data subject of the refusal.
Question 7: An organization's DPO raises an objection to a new marketing initiative on data protection grounds, but senior management overrules it. What GDPR principle is at risk?
- Accountability under Article 5(2)
- The DPO's independence requirement under Article 38(3) (Correct answer)
- Data minimisation under Article 5(1)(c)
- The right to rectification under Article 16
Correct answer: The DPO's independence requirement under Article 38(3)
Article 38(3) prohibits the controller from instructing the DPO on how to perform their tasks; overruling a DPO's compliance objection violates their required independence.
A data subject submits a Subject Access Request (SAR) but fails to specify which processing activities they are inquiring about.
What is the controller's correct first step?