ITPEC IP October 2024 Question 75

Source exam: ITPEC IP October 2024Topic: Legal Affairs

ITPEC IP October 2024 — Question 75 of 100

Descriptions A and C are appropriate. A business with an establishment in the EU can be subject to GDPR for relevant processing in the context of that establishment, so A is valid. A business with no EU establishment that provides services only outside the EU and neither offers goods or services to people in the EU nor monitors their behavior there falls outside the situations described, so C is also valid.

Answer (c)

Why not others:
- B is false because an EU establishment does not automatically escape GDPR merely because recipients are outside the EU

- D is false because GDPR can apply extraterritorially when a non-EU business offers goods or services to people in the EU or monitors behavior there

- options (a), (b), and (d) therefore omit C or include an incorrect statement

Key rule: GDPR scope can arise from an EU establishment or from specified targeting or monitoring of people in the EU.

AI-generated — may contain errors

The original exam layout is preserved in the image so diagrams, formulas, tables, and code remain accurate.

This question comes from an official ITPEC past paper. ITPEC Practice is an independent study tool and is not affiliated with ITPEC. See the official IP past-paper collection or Report an issue.