Certified Information Privacy Professional – Europe (CIPP/E) — Question 114
Which of the following Convention 108+ principles, as amended in 2018, is NOT consistent with a principle found in the GDPR?
Answer options
- A. The obligation of companies to declare data breaches.
- B. The requirement to demonstrate compliance to a supervisory authority.
- C. The lawfulness of the bulk collection of personal data by the government.
- D. The necessity of establishing a specific legal basis for processing personal data.
Correct answer: C
Explanation
Option C is correct because the GDPR emphasizes the protection of personal data and does not support the bulk collection of personal data by governments without specific legal grounds. Options A, B, and D are consistent with GDPR principles, as they all promote transparency, compliance, and legal justification in data processing.