In which scenario is a Controller most likely required to undertake a Data Protection Impact Assessment?
When assessing the level of risk created by a data breach, which of the following would NOT have to be taken into consideration?
The GDPR forbids the practice of "forum shopping", which occurs when companies do what?
A company plans to transfer employee health information between two of its entities in France. To maintain the security of the processing, what would be the most important security measure to apply to the health data transmission?
What should a controller do after a data subject opts out of a direct marketing activity?