GDPR Troubleshooting & Problem Resolution 3 — Questions and Answers
Question 1: A supervisory authority issues an enforcement notice requiring a controller to stop a specific processing activity within 14 days. The controller believes the notice is incorrect. What is the appropriate response?
- Ignore the notice pending internal review
- Continue processing and notify affected data subjects
- Comply with the notice while exercising the right to appeal via Article 78 (Correct answer)
- Escalate to the EDPB for immediate intervention
Correct answer: Comply with the notice while exercising the right to appeal via Article 78
Article 78 grants controllers the right to an effective judicial remedy against a supervisory authority decision, but compliance with an enforcement notice is generally required while appealing.
Question 2: A user complains that the privacy notice they received at data collection did not mention data sharing with a subsidiary. What Article 13 element was omitted?
- The contact details of the lead supervisory authority
- The recipients or categories of recipients of the personal data (Correct answer)
- The data subject's right to lodge a complaint with an SA
- The legal basis for any subsequent international transfers
Correct answer: The recipients or categories of recipients of the personal data
Article 13(1)(e) requires controllers to inform data subjects of recipients or categories of recipients at the time data is collected.
Question 3: An organization running automated credit-scoring decisions receives a complaint that an applicant was not informed of the logic involved. Which Article was breached?
- Article 22(3) — failure to provide meaningful information about the logic of automated decisions (Correct answer)
- Article 17 — failure to erase data used in the decision
- Article 20 — failure to provide data portability
- Article 25 — failure to implement privacy by design
Correct answer: Article 22(3) — failure to provide meaningful information about the logic of automated decisions
Article 22(3) requires controllers to provide meaningful information about the logic, significance, and envisaged consequences of solely automated decisions.
Question 4: During a post-incident review, it is discovered that the breach notification to the supervisory authority was sent within 72 hours but lacked details on the approximate number of affected individuals. What is the correct remediation?
- File a completely new notification to replace the original
- Submit supplementary information to the SA as soon as it becomes available (Correct answer)
- Close the incident because the 72-hour deadline was met
- Inform all affected individuals that the SA was notified
Correct answer: Submit supplementary information to the SA as soon as it becomes available
Article 33(4) expressly allows phased notifications; where not all information is available, controllers may provide it in phases without undue delay.
Question 5: A controller in the US transfers EU personal data to a cloud provider in India without any transfer mechanism in place. What is the most immediate compliance problem?
- Failure to conduct a DPIA before the transfer
- An unlawful third-country transfer in violation of Chapter V GDPR (Correct answer)
- Non-compliance with Article 28 processor obligations
- A breach of the data minimisation principle
Correct answer: An unlawful third-country transfer in violation of Chapter V GDPR
Chapter V of the GDPR prohibits transfers to third countries lacking adequacy decisions unless appropriate safeguards such as SCCs are in place.
Question 6: A data subject exercises the right to restriction of processing. The controller continues to send the individual marketing emails. What violation has occurred?
- Violation of Article 18 — processing continued beyond the permitted scope during restriction (Correct answer)
- Violation of Article 21 — the right to object was ignored
- Violation of Article 15 — access rights were not fulfilled
- Violation of Article 17 — the data should have been erased immediately
Correct answer: Violation of Article 18 — processing continued beyond the permitted scope during restriction
Under Article 18(2), once restriction is applied, personal data may only be processed with the data subject's consent or for limited legal purposes; continued marketing violates this.
Question 7: An organization finds that its Article 30 records of processing activities have not been updated to reflect a new HR system introduced eight months ago. What is the risk?
- Immediate personal data breach notification obligation to the SA
- Non-compliance with Article 30 accountability documentation requirements (Correct answer)
- Automatic suspension of the lawful basis for HR processing
- Mandatory appointment of a DPO if one was not previously required
Correct answer: Non-compliance with Article 30 accountability documentation requirements
Article 30 requires records to be kept up to date; failure to document a processing activity is an accountability breach that supervisory authorities can investigate and sanction.
A supervisory authority issues an enforcement notice requiring a controller to stop a specific processing activity within 14 days.
The controller believes the notice is incorrect.
What is the appropriate response?