IAPP Certified Information Privacy Professional/Europe (CIPP/E) CIPP-E Question # 83 Topic 9 Discussion

IAPP Certified Information Privacy Professional/Europe (CIPP/E) CIPP-E Question # 83 Topic 9 Discussion

CIPP-E Exam Topic 9 Question 83 Discussion:
Question #: 83
Topic #: 9

According to the European Data Protection Board, if a controller that is not established in the EU but still subject to the GDPR becomes aware of a personal data breach, which supervisory authority or authorities must be notified?


A.

Only the supervisory authority of the EU member state in which the controller's EU representative (pursuant to Article 27) is established.


B.

Only one lead supervisory authority, as a controller benefits from the one-stop shop mechanism under the GDPR's enforcement regime.


C.

Every supervisory authority of the EU member states where the controller is offering goods or services.


D.

Every supervisory authority for which affected data subjects reside in their EU member state.


Get Premium CIPP-E Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.