View all questions & answers for the CIPP-E exam
Under the GDPR, which essential pieces of information must be provided to data subjects before collecting their personal data?
The authority by which the controller is collecting the data and the third parties to whom the data will be sent.
The name/s of relevant government agencies involved and the steps needed for revising the data.
The identity and contact details of the controller and the reasons the data is being collected.
The contact information of the controller and a description of the retention policy.
The GDPR requires that data subjects are provided with certain information when their personal data are collected, either from the data subject themselves or from another source12. This information includes, among other things, the identity and contact details of the controller (and, where applicable, of the controller’s representative and the data protection officer), and the purposes of the processing for which the personal data are intended as well as the legal basis for the processing34. This information is necessary to ensure fair and transparent processing of personal data, and to enable data subjects to exercise their rights under the GDPR5. Therefore, option C is the correct answer, as it contains two of the essential pieces of information that must be provided to data subjects before collecting their personal data. Options A, B and D are incorrect, as they do not include all the required information or include information that is not mandatory. References: 1: Article 13 of the GDPR 2: Article 14 of the GDPR 3: Article 13(1)(a) and © of the GDPR 4: Article 14(1)(a) and © of the GDPR 5: Recital 60 of the GDPR
Submit