GDPR Extra cases Flashcards

(7 cards)

1
Q

An online clothing store collects usersโ€™ email addresses during checkout. One week later, it sends them marketing emails โ€” but users were never asked if they agree.
๐Ÿ‘‰ Is this allowed?

A

Issue: Sending marketing emails without consent

Rule: Article 6(1)(a) โ€“ Processing must be based on clear consent

Application: The users didnโ€™t agree to marketing. The company canโ€™t assume consent.

Conclusion: โŒ This is illegal โ€“ GDPR requires freely given and informed consent for marketing.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

A hospital stores patient records without encryption. A hacker later steals thousands of health records.
๐Ÿ‘‰ What kind of GDPR issue is this?

A

Issue: Data breach and lack of security

Rule: Article 5(1)(f) โ€“ Data must be stored with confidentiality and integrity

Application: Medical data is sensitive; no encryption = weak protection

Conclusion: โŒ This is a GDPR breach โ€“ the hospital didnโ€™t use proper security.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

A 13-year-old signs up for a social media app by checking a box that says โ€œI accept the terms.โ€ The app is based in Belgium.
๐Ÿ‘‰ Is this valid consent under the GDPR?

A

Issue: Consent by a minor under 16

Rule: Article 8 โ€“ Children must be at least 16 (or 13 if national law allows)

Application: Belgium follows the default 16 rule unless changed by national law

Conclusion: โŒ Probably invalid consent โ€“ unless parental permission was obtained.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

A survey company keeps peopleโ€™s answers (with names and addresses) for 10 years โ€” even though the research project ended after 6 months.
๐Ÿ‘‰ Does this respect the GDPR?

A

Issue: Keeping personal data longer than necessary

Rule: Article 5(1)(e) โ€“ Storage limitation principle

Application: The data is kept much longer than needed for the purpose

Conclusion: โŒ This violates GDPR โ€“ data must be deleted when itโ€™s no longer needed.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Q (Front):
A small company collects customersโ€™ phone numbers for delivery, but then uses them to send product promotions without telling them.
๐Ÿ‘‰ What GDPR principle is being broken?

A

Issue: Using data for a different purpose than originally stated

Rule: Article 5(1)(b) โ€“ Purpose limitation

Application: Customers gave data for delivery only, not ads

Conclusion: โŒ This is illegal โ€“ the company needs separate consent for promotions.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

A website says โ€œBy using our site, you automatically agree to all data use.โ€ It does not provide any explanation or option to say no.
๐Ÿ‘‰ Is this valid GDPR consent?

A

Issue: No real, informed consent

Rule: Article 7 โ€“ Consent must be freely given, specific, and informed

Application: โ€œAutomatic consentโ€ without explanation is not valid

Conclusion: โŒ This is not valid consent under the GDPR.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Q (Front):
A company processes biometric data (like facial recognition) for office security, but doesnโ€™t inform employees or ask for their permission.
๐Ÿ‘‰ What kind of data is this and is it allowed?

A

Issue: Processing sensitive data without consent

Rule: Article 9 โ€“ Biometric data = special category

Application: Biometric data needs explicit consent or strong legal reason

Conclusion: โŒ Illegal โ€“ unless the company has clear legal basis and informs staff.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly