Certified Information Privacy Professional – Europe (CIPP/E) — Question 203
Which of the following is the weakest lawful basis for processing employee personal data?
Answer options
- A. Processing based on fulfilling an employment contract.
- B. Processing based on employee consent.
- C. Processing based on legitimate interests.
- D. Processing based on legal obligation.
Correct answer: B
Explanation
The correct answer is B, as processing based on employee consent can be withdrawn at any time, making it the least reliable lawful basis. In contrast, fulfilling an employment contract, legitimate interests, and legal obligations are more robust grounds that typically cannot be easily revoked.