Winter Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: pass65

Exam CIPP-E All Questions
Exam CIPP-E All Questions

View all questions & answers for the CIPP-E exam

IAPP Certified Information Privacy Professional CIPP-E Question # 7 Topic 1 Discussion

CIPP-E Exam Topic 1 Question 7 Discussion:
Question #: 7
Topic #: 1

SCENARIO

Please use the following to answer the next question:

Gentle Hedgehog Inc. is a privately owned website design agency incorporated in

Italy. The company has numerous remote workers in different EU countries. Recently,

the management of Gentle Hedgehog noticed a decrease in productivity of their sales

team, especially among remote workers. As a result, the company plans to implement

a robust but privacy-friendly remote surveillance system to prevent absenteeism,

reward top performers, and ensure the best quality of customer service when sales

people are interacting with customers.

Gentle Hedgehog eventually hires Sauron Eye Inc., a Chinese vendor of employee

surveillance software whose European headquarters is in Germany. Sauron Eye's

software provides powerful remote-monitoring capabilities, including 24/7 access to

computer cameras and microphones, screen captures, emails, website history, and

keystrokes. Any device can be remotely monitored from a central server that is

securely installed at Gentle Hedgehog headquarters. The monitoring is invisible by

default; however, a so-called Transparent Mode, which regularly and conspicuously

notifies all users about the monitoring and its precise scope, also exists. Additionally,

the monitored employees are required to use a built-in verification technology

involving facial recognition each time they log in.

All monitoring data, including the facial recognition data, is securely stored in Microsoft Azure cloud servers operated by Sauron Eye, which are physically located in France.

Under what condition could the surveillance system be used on the personal devices

of employees?


A.

Only if the monitoring system is manufactured by a European vendor storing the monitoring data within the EU.


B.

Only if the employees give valid consent and the monitoring is narrowly limited to their professional tasks.


C.

Only if the cloud that stores the monitoring data is certified by the EDPB as GDPR compliant.


D.

Only if the employer offers an adequate compensation for using the employee's devices.


Get Premium CIPP-E Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.