Certified Information Privacy Professional – Europe (CIPP/E) — Question 206
SCENARIO -
Please use the following to answer the next question:
ABC Hotel Chain and XYZ Travel Agency are U.S.-based multinational companies. They use an internet-based common platform for collecting and sharing their customer data with each other, in order to integrate their marketing efforts. Additionally, they agree on the data to be stored, how reservations will be booked and confirmed, and who has access to the stored data.
Mike, an EU resident, has booked travel itineraries in the past through XYZ Travel Agency to stay at ABC Hotel Chain’s locations. XYZ Travel Agency offers a rewards program that allows customers to sign up to accumulate points that can later be redeemed for free travel. Mike has signed the agreement to be a rewards program member.
Now Mike wants to know what personal information the company holds about him. He sends an email requesting access to his data, in order to exercise what he believes are his data subject rights.
What are ABC Hotel Chain and XYZ Travel Agency’s roles in this relationship?
Answer options
- A. ABC Hotel Chain is the controller and XYZ Travel Agency is the processor.
- B. XYZ Travel Agency is the controller and ABC Hotel Chain is the processor.
- C. ABC Hotel Chain and XYZ Travel Agency are independent controllers.
- D. ABC Hotel Chain and XYZ Travel Agency are joint controllers.
Correct answer: D
Explanation
The correct answer is D because both ABC Hotel Chain and XYZ Travel Agency jointly determine the purposes and means of processing the personal data, making them joint controllers. Options A and B incorrectly assign the roles of controller and processor to one party, while option C suggests they are independent without acknowledging their collaborative role.