CIPP-A Exam QuestionsBrowse all questions from this exam

CIPP-A Exam - Question 53


SCENARIO – Please use the following to answer the next question:

Dracarys Inc. is a large multinational company with headquarters in Seattle, Washington, U.S.A. Dracarys began as a small company making and selling women's clothing, but rapidly grew through its early innovative use of online platforms to sell its products. Dracarys is now one of the biggest names in the industry, and employs staff across the globe, and in Asia has employees located in both Singapore and Hong Kong.

Due to recent management restructuring they have decided, on the advice of external consultants, to open an office in India in order to centralize its call center as well as its internal human resource functions for the Asia region. Dracarys would like to centralize the following human resource functions in India:

1. The recruitment process;

2. Employee assessment and records management;

3. Employee benefits administration, including health insurance.

Dracarys will have employees on the ground in India managing the systems for the functions listed above. They have been presented with a variety of vendor options for these systems, and are currently assessing the suitability of these vendors for their needs.

The CEO of Dracarys is concerned about the behavior of her employees, especially online. After having proprietary company information being shared with competitors by former employees, she is eager to put certain measures in place to ensure that the activities of her employees, while on Dracarys' premises or when using any of Dracarys' computers and networks are not detrimental to the business.

Dracarys' external consultants are also advising the company on how to increase earnings. Dracary's management refuses to reduce production costs and compromise the quality of their garments, so the consultants suggested utilizing customer data to create targeted advertising and thus increase sales.

Dracarys and their vendor of choice must draft a contract that establishes agreement regarding all of the following factors EXCEPT?

Show Answer
Correct Answer: CD

The contract between Dracarys and their vendor of choice must cover factors that ensure the protection of data and address the company's specific needs with regard to their human resource functions. These include breach notification, data retention periods, and data subject consent provisions, all of which are essential for managing and protecting data in accordance with laws and regulations. However, the employee recruitment process is an internal function specific to Dracarys, not a data protection or vendor-related matter. Therefore, the employee recruitment process does not need to be included in the contract with the vendor.

Discussion

2 comments
Sign in to comment
rhyst1921Option: D
Mar 22, 2024

Answer is D, because data subject consent, if required, should be obtained by Dracarys Inc and not the vendor.

BhimeshOption: D
Mar 30, 2024

D - Data subject consent provisions Vendor is a processor and Dracarys is a controller, the controller takes care of consent. Vendor will be looking after the following functions and their privacy policy must be aligned with Dracarys… Human resource functions in India: 1. The recruitment process; 2. Employee assessment and records management; 3. Employee benefits administration, including health insurance. Data Intermediary - The DI is referred to differently depending upon the country or jurisdiction. In Singapore, it is data intermediary. in EU – the data processor, And in the United States – a data processor is typically referred to as a vendor, service provider or a third-party service provider.