Certified Information Privacy Manager (CIPM) — Question 24
Which of the following information must be provided by the data controller when complying with GDPR “right to be informed” requirements?
Answer options
- A. The purpose of personal data processing.
- B. The data subject’s right to withdraw consent.
- C. The contact details of the Data Protection Officer (DPO).
- D. The name of any organizations with whom personal data was shared.
Correct answer: A
Explanation
The correct answer is A because GDPR mandates that data controllers must inform individuals about the purpose of processing their personal data. Options B, C, and D, while important, do not directly fulfill the requirement of disclosing the purpose of data processing.