GDPR Extra cases Flashcards
(7 cards)
An online clothing store collects usersโ email addresses during checkout. One week later, it sends them marketing emails โ but users were never asked if they agree.
๐ Is this allowed?
Issue: Sending marketing emails without consent
Rule: Article 6(1)(a) โ Processing must be based on clear consent
Application: The users didnโt agree to marketing. The company canโt assume consent.
Conclusion: โ This is illegal โ GDPR requires freely given and informed consent for marketing.
A hospital stores patient records without encryption. A hacker later steals thousands of health records.
๐ What kind of GDPR issue is this?
Issue: Data breach and lack of security
Rule: Article 5(1)(f) โ Data must be stored with confidentiality and integrity
Application: Medical data is sensitive; no encryption = weak protection
Conclusion: โ This is a GDPR breach โ the hospital didnโt use proper security.
A 13-year-old signs up for a social media app by checking a box that says โI accept the terms.โ The app is based in Belgium.
๐ Is this valid consent under the GDPR?
Issue: Consent by a minor under 16
Rule: Article 8 โ Children must be at least 16 (or 13 if national law allows)
Application: Belgium follows the default 16 rule unless changed by national law
Conclusion: โ Probably invalid consent โ unless parental permission was obtained.
A survey company keeps peopleโs answers (with names and addresses) for 10 years โ even though the research project ended after 6 months.
๐ Does this respect the GDPR?
Issue: Keeping personal data longer than necessary
Rule: Article 5(1)(e) โ Storage limitation principle
Application: The data is kept much longer than needed for the purpose
Conclusion: โ This violates GDPR โ data must be deleted when itโs no longer needed.
Q (Front):
A small company collects customersโ phone numbers for delivery, but then uses them to send product promotions without telling them.
๐ What GDPR principle is being broken?
Issue: Using data for a different purpose than originally stated
Rule: Article 5(1)(b) โ Purpose limitation
Application: Customers gave data for delivery only, not ads
Conclusion: โ This is illegal โ the company needs separate consent for promotions.
A website says โBy using our site, you automatically agree to all data use.โ It does not provide any explanation or option to say no.
๐ Is this valid GDPR consent?
Issue: No real, informed consent
Rule: Article 7 โ Consent must be freely given, specific, and informed
Application: โAutomatic consentโ without explanation is not valid
Conclusion: โ This is not valid consent under the GDPR.
Q (Front):
A company processes biometric data (like facial recognition) for office security, but doesnโt inform employees or ask for their permission.
๐ What kind of data is this and is it allowed?
Issue: Processing sensitive data without consent
Rule: Article 9 โ Biometric data = special category
Application: Biometric data needs explicit consent or strong legal reason
Conclusion: โ Illegal โ unless the company has clear legal basis and informs staff.