Knowee
Questions
Features
Study Tools

Which of the following are available lawful basis under GDPR?  CO2Select one or more:a.Contractual Obligation (Controller and Data Subject)b.Data subject Interestc.Controller and processor contractd.Vital Interest

Question

Which of the following are available lawful basis under GDPR?  CO2Select one or more:a.Contractual Obligation (Controller and Data Subject)b.Data subject Interestc.Controller and processor contractd.Vital Interest

🧐 Not the exact question you are looking for?Go ask a question

Solution

The lawful bases for processing personal data under the General Data Protection Regulation (GDPR) include:

a. Contractual Obligation (Controller and Data Subject): This is a lawful basis if you need to process personal data to fulfil your contractual obligations with a data subject, or because they have asked you to do something before entering into a contract (like provide a quote).

b. Data Subject Interest: This is not a recognized lawful basis under GDPR. However, there is a similar concept called "Legitimate Interests". This can be used as a lawful basis if you have a genuine and legitimate reason (including commercial benefit), unless there is a good reason to protect the individual’s personal data which overrides those legitimate interests.

c. Controller and Processor Contract: This is not a recognized lawful basis under GDPR. The relationship between a controller and a processor needs to be established by a contract, but it's not a lawful basis for processing.

d. Vital Interest: This can be a lawful basis for processing personal data, but it is very limited in its scope. It generally only applies to matters of life and death, for example if an individual’s medical history is disclosed to a hospital’s A&E department treating them after a serious road accident.

So, the correct answers are a. Contractual Obligation (Controller and Data Subject) and d. Vital Interest.

This problem has been solved

Similar Questions

Under GDPR, which of the following is not a measure for International Data Transfer? CO2 a. Safe Countries b. Standard Contractual Clauses c. Privacy Policy d. Binding Corporate Rule

ABC company has outsourced its personal database operations and storage to DEF company. Identify the role as per GDPR CO3a.ABC is controller and DEF is processorb.ABC and DEF both are processorc.ABC and DEF do not have any relationd.ABC is processor and DEF is controller

Which one of the following elements is not necessary for a contract?Question 4Answera.  Competent partiesb.Lawful concentration.c.Reasonable terms and conditionsd.Free consentClear my choice

Information they have must be confidential for the GDPR. Explain what this is and what the principles are.

Which of the following are publicly available framework used in designing internal control:Question 2AnswerSelect one:a.legislation or regulationb.COSO and COBITc.industry standardd.all of the options are correct

1/1

Upgrade your grade with Knowee

Get personalized homework help. Review tough concepts in more detail, or go deeper into your topic by exploring other relevant questions.