Question 1 of 30
A multinational corporation processes personal data of EU citizens for marketing purposes. The company has implemented various security measures to protect this data. However, a data breach occurs, exposing sensitive information. Under the GDPR, what are the primary responsibilities of the company in response to this incident, particularly regarding notification and documentation requirements?
The company must notify the relevant supervisory authority within 72 hours of becoming aware of the breach and inform affected individuals if there is a high risk to their rights and freedoms. Additionally, it must document the breach, including its effects and the remedial actions taken.
The company is only required to notify affected individuals if the breach results in financial loss to them, and there is no need to inform the supervisory authority unless the breach is severe.
The company must notify the supervisory authority within 48 hours and is not required to inform affected individuals unless they request it. Documentation of the breach is optional.
The company should only document the breach internally and is not required to notify anyone unless a formal complaint is filed against them.

Preparing for CISCO 300-720 Securing Email with Cisco Email Security Appliance (SESA)? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free