CIPP-E Exam QuestionsBrowse all questions from this exam

CIPP-E Exam - Question 90


SCENARIO -

Please use the following to answer the next question:

BHealthy, a company based in Italy, is ready to launch a new line of natural products, with a focus on sunscreen. The last step prior to product launch is for BHealthy to conduct research to decide how extensively to market its new line of sunscreens across Europe. To do so, BHealthy teamed up with Natural Insight, a company specializing in determining pricing for natural products. BHealthy decided to share its existing customer information – name, location, and prior purchase history – with Natural Insight. Natural Insight intends to use this information to train its algorithm to help determine the price point at which BHealthy can sell its new sunscreens.

Prior to sharing its customer list, BHealthy conducted a review of Natural Insight’s security practices and concluded that the company has sufficient security measures to protect the contact information. Additionally, BHealthy’s data processing contractual terms with Natural Insight require continued implementation of technical and organization measures. Also indicated in the contract are restrictions on use of the data provided by BHealthy for any purpose beyond provision of the services, which include use of the data for continued improvement of Natural Insight’s machine learning algorithms.

What is the nature of BHealthy and Natural Insight’s relationship?

Show Answer
Correct Answer: A

Natural Insight is BHealthy’s processor because the companies entered into data processing terms. When BHealthy shares its customer data with Natural Insight under a specific contract that dictates how the data should be handled and limits its use for purposes defined by BHealthy, such as training an algorithm to determine pricing, Natural Insight is acting as a data processor. The primary determinant is the contract and defined roles, not the security measures or individual usage of the data for algorithm training.

Discussion

4 comments
Sign in to comment
EgofskamOption: D
Aug 16, 2023

I really think it is D given Natural Insight is determining the purpose for processing. While C is close, BHealthy is actually a controller because of its use and control of the data, not because its intent to determine pricing information...

hele_meneerOption: D
Dec 27, 2023

D, because BH did not set the means and goals of using the data to train NI's AI

moxiangnaichaOption: A
Nov 19, 2023

I agree with A.

tubcippeOption: A
Nov 14, 2023

A should be the answer