GDPR Practice Question: A ransomware attack that encrypts personal data and the organization... | CyberCertPrep
EUGDPRBreach NotificationEASYFree question
A ransomware attack that encrypts personal data and the organization has no backup constitutes:
A.A breach only if ransom is paid, citing Article 4(12)'s definition of personal data breach, which requires proof that data was actually misused, not merely accessed
B.An availability breach (and potentially a confidentiality breach if data was also exfiltrated)
C.Only an IT security incident, not a GDPR breach
D.Only a criminal matter
Why B is correct
Ransomware causing loss of data availability is a personal data breach. If data was also exfiltrated, it's also a confidentiality breach.
Know someone studying for GDPR? Send them this one.
Where this fits in the GDPR exam
Breach Notification
Covers breach notification concepts and practices within GDPR.
This question belongs to the "Data Protection by Design & Default" domain, which makes up about 15% of the GDPR exam.
CyberCertPrep gives you 20 free GDPR questions per day with this same answer-and-explanation depth, plus timed exam simulations and progress tracking. No card required.
GDPR and EU are trademarks or registered trademarks of their respective owners. CyberCertPrep is an independent exam-preparation resource and is not affiliated with, authorized by, sponsored by, or endorsed by EU or any other certification body. All study material is independently created; the certification name is used only to identify the exam this resource helps you prepare for.
Under GDPR, what constitutes a 'personal data breach'?