
[Apr-2023] IAPP CIPP-E Exam: Basic Questions With Answers
New 2023 Realistic Free IAPP CIPP-E Exam Dump Questions and Answer
NEW QUESTION # 103
Article 5(1)(b) of the GDPR states that personal data must be "collected for specified, explicit and legitimate purposes and not further processed in a way incompatible with those purposes." Based on Article 5(1)(b), what is the impact of a member state's interpretation of the word "incompatible"?
- A. It dictates the level of security a processor must follow when using and storing personal data for two different purposes.
- B. It guides the courts on the severity of the consequences for those who are convicted of the intentional misuse of personal data.
- C. It sets the standard for the level of detail a controller must record when documenting the purpose for collecting personal data.
- D. It indicates the degree of flexibility a controller has in using personal data in ways that may vary from its original intended purpose.
Answer: A
NEW QUESTION # 104
It a company receives an anonymous email demanding ransom for the stolen personal data of its clients, what must the company do next, per GDPR requirements'3
- A. Start an investigation to understand the incident's possible scope, duration and nature
- B. Send an email about the incident to all clients and ask them to change their passwords
- C. Send a notification to the competent supervisory authority describing the incident.
- D. Notify the police and Tile a criminal complaint about the incident
Answer: C
NEW QUESTION # 105
Please use the following to answer the next question:
Due to rapidly expanding workforce, Company A has decided to outsource its payroll function to Company B. Company B is an established payroll service provider with a sizable client base and a solid reputation in the industry.
Company B's payroll solution for Company A relies on the collection of time and attendance data obtained via a biometric entry system installed in each of Company A's factories. Company B won't hold any biometric data itself, but the related data will be uploaded to Company B's UK servers and used to provide the payroll service. Company B's live systems will contain the following information for each of Company A's employees:
Name
Address
Date of Birth
Payroll number
National Insurance number
Sick pay entitlement
Maternity/paternity pay entitlement
Holiday entitlement
Pension and benefits contributions
Trade union contributions
Jenny is the compliance officer at Company A. She first considers whether Company A needs to carry out a data protection impact assessment in relation to the new time and attendance system, but isn't sure whether or not this is required.
Jenny does know, however, that under the GDPR there must be a formal written agreement requiring Company B to use the time and attendance data only for the purpose of providing the payroll service, and to apply appropriate technical and organizational security measures for safeguarding the data. Jenny suggests that Company B obtain advice from its data protection officer. The company doesn't have a DPO but agrees, in the interest of finalizing the contract, to sign up for the provisions in full. Company A enters into the contract.
Weeks later, while still under contract with Company A, Company B embarks upon a separate project meant to enhance the functionality of its payroll service, and engages Company C to help. Company C agrees to extract all personal data from Company B's live systems in order to create a new database for Company B.
This database will be stored in a test environment hosted on Company C's U.S. server. The two companies agree not to include any data processing provisions in their services agreement, as data is only being used for IT testing purposes.
Unfortunately, Company C's U.S. server is only protected by an outdated IT security system, and suffers a cyber security incident soon after Company C begins work on the project. As a result, data relating to Company A's employees is visible to anyone visiting Company C's website. Company A is unaware of this until Jenny receives a letter from the supervisory authority in connection with the investigation that ensues. As soon as Jenny is made aware of the breach, she notifies all affected employees.
The GDPR requires sufficient guarantees of a company's ability to implement adequate technical and organizational measures. What would be the most realistic way that Company B could have fulfilled this requirement?
- A. Hiring companies whose measures are consistent with recommendations of accrediting bodies.
- B. Requesting advice and technical support from Company A's IT team.
- C. Vetting companies' measures with the appropriate supervisory authority.
- D. Avoiding the use of another company's data to improve their own services.
Answer: A
NEW QUESTION # 106
What is the consequence if a processor makes an independent decision regarding the purposes and means of processing it carries out on behalf of a controller?
- A. The processor will be considered to be a controller in respect of the processing concerned
- B. The processor will be liable to pay compensation to affected data subjects
- C. The controller will be liable to pay an administrative fine
- D. The controller will be required to demonstrate that the unauthorized processing negatively affected one or more of the parties involved
Answer: B
NEW QUESTION # 107
What is the MAIN reason GDPR Article 4(22) establishes the concept of the "concerned supervisory authority"?
- A. To ensure that the interests of individuals residing outside the lead authority's jurisdiction are represented.
- B. To encourage the consistency of local data processing activity.
- C. To give corporations a choice about who their supervisory authority will be.
- D. To ensure the GDPR covers controllers that do not have an establishment in the EU but have a representative in a member state.
Answer: B
NEW QUESTION # 108
Please use the following to answer the next question:
ProStorage is a multinational cloud storage provider headquartered in the Netherlands. Its CEO. Ruth Brown, has developed a two-pronged strategy for growth: 1) expand ProStorage s global customer base and 2) increase ProStorage's sales force by efficiently onboarding effective teams. Enacting this strategy has recently been complicated by Ruth's health condition, which has limited her working hours, as well as her ability to travel to meet potential customers. ProStorage's Human Resources department and Ruth's Chief of Staff now work together to manage her schedule and ensure that she is able to make all her medical appointments The latter has become especially crucial after Ruth's last trip to India, where she suffered a medical emergency and was hospitalized m New Delhi Unable to reach Ruths family, the hospital reached out to ProStorage and was able to connect with her Chief of Staff, who in coordination with Mary, the head of HR. provided information to the doctors based on accommodate on requests Ruth made when she started a: ProStorage Why is the additional measure recommended by Jackie sufficient foe using UpFinance?
- A. UpFinance implements sufficient data protection measures
- B. UpFinance is an established 7-year-old business.
- C. UpFinance is in a highly regulated financial industry
- D. UpFinance is based in a country without surveillance laws.
Answer: D
NEW QUESTION # 109
Based on GDPR Article 35, which of the following situations would trigger the need to complete a DPIA?
- A. A company wants to use location data to infer information on a person's clothes purchasing habits.
- B. A company wants to build a dating app that creates candidate profiles based on location data and data from third-party sources.
- C. A company wants to combine location data with other data in order to offer more personalized service for the customer.
- D. A company wants to use location data to track delivery trucks in order to make the routes more efficient.
Answer: B
Explanation:
Reference http://webcache.googleusercontent.com/search?q=cache:aQkU17eX9sQJ:https:// www.shlegal.com/insights/article-29-data-protection-working-party-gdpr-guidelines-on-data-protection-impact- assessments&client=firefox-b-e&hl=en&gl=pk&strip=1&vwsrc=0
NEW QUESTION # 110
In 2016's Guidance, the United Kingdom's Information Commissioner's Office (ICO) reaffirmed the importance of using a "layered notice" to provide data subjects with what?
- A. An efficient means of providing written consent in member states where they are required to do so.
- B. A privacy notice explaining the consequences for opting out of the use of cookies on a website.
- C. An explanation of the security measures used when personal data is transferred to a third party.
- D. A privacy notice containing brief information whilst offering access to further detail.
Answer: C
NEW QUESTION # 111
SCENARIO
Please use the following to answer the next question:
Jack worked as a Pharmacovigiliance Operations Specialist in the Irish office of a multinational pharmaceutical company on a clinical trial related to COVID-19. As part of his onboarding process Jack received privacy training He was explicitly informed that while he would need to process confidential patient data in the course of his work, he may under no circumstances use this data for anything other than the performance of work-related (asks This was also specified in the privacy policy, which Jack signed upon conclusion of the training.
After several months of employment, Jack got into an argument with a patient over the phone. Out of anger he later posted the patient's name and hearth information, along with disparaging comments, on a social media website. When this was discovered by his Pharmacovigilance supervisors. Jack was immediately dismissed Jack's lawyer sent a letter to the company stating that dismissal was a disproportionate sanction, and that if Jack was not reinstated within 14 days his firm would have no alternative but to commence legal proceedings against the company. This letter was accompanied by a data access request from Jack requesting a copy of "all personal data, including internal emails that were sent/received by Jack or where Jack is directly or indirectly identifiable from the contents In relation to the emails Jack listed six members of the management team whose inboxes he required access.
The company conducted an initial search of its IT systems, which returned a large amount of information They then contacted Jack, requesting that he be more specific regarding what information he required, so that they could carry out a targeted search Jack responded by stating that he would not narrow the scope of the information requester.
Under Article 82 of the GDPR ("Right to compensation and liability-), which party is liable for the damage caused by the data breach?
- A. The pharmaceutical company is liable.
- B. Jack is liable
- C. Jack and the pharmaceutical company are jointly liable.
- D. Both parties are exempt, as the company is involved in human health research
Answer: C
NEW QUESTION # 112
Under which of the following conditions does the General Data Protection Regulation NOT apply to the processing of personal data?
- A. When the personal data is processed by an individual only for their household activities
- B. When the personal data is held by the controller but not processed for further purposes
- C. When the personal data is processed only in non-electronic form
- D. When the personal data is collected and then pseudonymised by the controller
Answer: D
Explanation:
Explanation/Reference: https://gdpr-info.eu/art-6-gdpr/
NEW QUESTION # 113
Which institution has the power to adopt findings that confirm the adequacy of the data protection level in a non-EU country?
- A. The Article 29 Working Party
- B. The European Commission
- C. The European Parliament
- D. The European Council
Answer: B
NEW QUESTION # 114
Which sentence BEST summarizes the concepts of "fairness," "lawfulness" and "transparency", as expressly required by Article 5 of the GDPR?
- A. Fairness refers to the collection of data from diverse subjects; lawfulness refers to the need for legal rules to be uniform; transparency refers to giving individuals access to their data.
- B. Fairness refers to limiting the amount of data collected from individuals; lawfulness refers to the approval of company guidelines by the state; transparency solely relates to communication of key information before collecting data.
- C. Fairness and transparency refer to the communication of key information before collecting data; lawfulness refers to compliance with government regulations.
- D. Fairness refers to the security of personal data; lawfulness and transparency refers to the analysis of ordinances to ensure they are uniformly enforced.
Answer: C
Explanation:
Explanation
NEW QUESTION # 115
Which type of personal data does the GDPR define as a "special category" of personal data?
- A. Trade-union membership.
- B. Educational history.
- C. Closed Circuit Television (CCTV) footage.
- D. Financial information.
Answer: A
Explanation:
Reference https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection- regulation-gdpr/lawful-basis-for-processing/special-category-data/#:~:text=The%20GDPR%20defines% 20special%20category%20data%20as%3A&text=personal%20data%20revealing%20trade%20union,used% 20for%20identification%20purposes)%3B
NEW QUESTION # 116
SCENARIO
Please use the following to answer the next question:
BHealthy, a company based in Italy, is ready to launch a new line of natural products, with a focus on sunscreen. The last step prior to product launch is for BHealthy to conduct research to decide how extensively to market its new line of sunscreens across Europe. To do so, BHealthy teamed up with Natural Insight, a company specializing in determining pricing for natural products. BHealthy decided to share its existing customer information - name, location, and prior purchase history - with Natural Insight. Natural Insight intends to use this information to train its algorithm to help determine the price point at which BHealthy can sell its new sunscreens.
Prior to sharing its customer list, BHealthy conducted a review of Natural Insight's security practices and concluded that the company has sufficient security measures to protect the contact information. Additionally, BHealthy's data processing contractual terms with Natural Insight require continued implementation of technical and organization measures. Also indicated in the contract are restrictions on use of the data provided by BHealthy for any purpose beyond provision of the services, which include use of the data for continued improvement of Natural Insight's machine learning algorithms.
Under the GDPR, what are Natural Insight's security obligations with respect to the customer information it received from BHealthy?
- A. Absolute security since BHealthy is sharing personal data, including purchase history, with Natural Insight.
- B. Only the security measures assessed by BHealthy prior to entering into the data processing contract.
- C. Appropriate security that takes into account the industry practices for protecting customer contact information and purchase history.
- D. The level of security that a reasonable data subject whose data is processed would expect in relation to the data subject's purchase history.
Answer: C
NEW QUESTION # 117
SCENARIO
Please use the following to answer the next question:
ProStorage is a multinational cloud storage provider headquartered in the Netherlands. Its CEO. Ruth Brown, has developed a two-pronged strategy for growth: 1) expand ProStorage s global customer base and 2) increase ProStorage's sales force by efficiently onboarding effective teams. Enacting this strategy has recently been complicated by Ruth's health condition, which has limited her working hours, as well as her ability to travel to meet potential customers. ProStorage's Human Resources department and Ruth's Chief of Staff now work together to manage her schedule and ensure that she is able to make all her medical appointments The latter has become especially crucial after Ruth's last trip to India, where she suffered a medical emergency and was hospitalized m New Delhi Unable to reach Ruths family, the hospital reached out to ProStorage and was able to connect with her Chief of Staff, who in coordination with Mary, the head of HR. provided information to the doctors based on accommodate on requests Ruth made when she started a: ProStorage Why was Jackie correct in not completing a transfer impact assessment for HRYourWay?
- A. HRYourWay was ultimately not selected
- B. HRYourWay is not located in a third country.
- C. ProStorage will obtain consent for all transfers.
- D. ProStorage can rely on its Binding Corporate Rules
Answer: C
NEW QUESTION # 118
What are the obligations of a processor that engages a sub-processor?
- A. The processor must obtain the controller's specific written authorization and provide annual reports on the sub-processor's performance.
- B. The processor must give the controller prior written notice and perform a preliminary audit of the sub- processor.
- C. The processor must receive a written agreement that the sub-processor will be fully liable to the controller for the performance of its obligations in relation to the personal data concerned.
- D. The processor must obtain the consent of the controller and ensure the sub-processor complies with data processing obligations that are equivalent to those that apply to the processor.
Answer: C
Explanation:
Reference https://inplp.com/latest-news/article/gdpr-rights-and-obligations-of-sub-processors/
NEW QUESTION # 119
What ruling did the Planet 49 CJEU judgment make regarding the issue of pre-ticked boxes?
- A. They are allowed if determined to be technically necessary.
- B. They constitute valid consent if the processing is necessary for purposes of legitimate interest
- C. They are allowed if recorded In the register of processing activities.
- D. They do not amount to valid consent under any circumstances.
Answer: D
NEW QUESTION # 120
SCENARIO
Please use the following to answer the next question:
BHealthy, a company based in Italy, is ready to launch a new line of natural products, with a focus on sunscreen. The last step prior to product launch is for BHealthy to conduct research to decide how extensively to market its new line of sunscreens across Europe. To do so, BHealthy teamed up with Natural Insight, a company specializing in determining pricing for natural products. BHealthy decided to share its existing customer information - name, location, and prior purchase history - with Natural Insight. Natural Insight intends to use this information to train its algorithm to help determine the price point at which BHealthy can sell its new sunscreens.
Prior to sharing its customer list, BHealthy conducted a review of Natural Insight's security practices and concluded that the company has sufficient security measures to protect the contact information. Additionally, BHealthy's data processing contractual terms with Natural Insight require continued implementation of technical and organization measures. Also indicated in the contract are restrictions on use of the data provided by BHealthy for any purpose beyond provision of the services, which include use of the data for continued improvement of Natural Insight's machine learning algorithms.
In which case would Natural Insight's use of BHealthy's data for improvement of its algorithms be considered data processor activity?
- A. If Natural Insight agrees to be fully liable for its use of BHealthy's customer information in its product improvement activities.
- B. If Natural Insight receives express contractual instructions from BHealthy to use its data for improving its algorithms.
- C. If Natural Insight satisfies the transparency requirement by notifying BHealthy's customers of its plans to use their information for its product improvement activities.
- D. If Natural Insight uses BHealthy's data for improving price point predictions only for BHealthy.
Answer: D
NEW QUESTION # 121
Bioface is a company based in the United States. It has no servers, personnel or assets in the European Union. By collecting photographs from social media and other web-based services, such as newspapers and blogs, it uses machine learning to develop a facial recognition algorithm. The algorithm identifies individuals in photographs who are not in its data set based the algorithm and its existing dat a. The service collects photographs of data subjects in the European Union and will identify them if presented with their photographs. Bioface offers its service to government agencies and companies in the United States and Canada, but not to those in the European Union. Bioface does not offer the service to individuals.
Why is Bioface subject to the territorial scope of the General Data Protection Regulation?
- A. It collects data from subjects and uses it for automated processing.
- B. It monitors the behavior of data subjects in the European Union.
- C. It collects data from European Union websites, which constitutes an establishment in the European Union.
- D. It offers services in the European Union by identifying data subjects in the European Union.
Answer: C
NEW QUESTION # 122
An organisation receives a request multiple times from a data subject seeking to exercise his rights with respect to his own personal dat a. Under what condition can the organisation charge the data subject for processing the request?
- A. Only where the organisation can show that it is reasonable to do so because more than one request was made.
- B. Only where the administrative costs of taking the action requested exceeds a certain threshold.
- C. Only if the organisation can demonstrate that the request is clearly excessive or misguided.
- D. Only to the extent this is allowed under the restrictions on data subjects' rights introduced under Art 23 of GDPR.
Answer: C
NEW QUESTION # 123
According to Article 14 of the GDPR, how long does a controller have to provide a data subject with necessary privacy information, if that subject's personal data has been obtained from other sources?
- A. Within a reasonable period after obtaining the personal data, but no later than one month.
- B. As soon as possible after obtaining the personal data.
- C. As soon as possible after the first communication with the data subject.
- D. Within a reasonable period after obtaining the personal data, but no later than eight weeks.
Answer: B
NEW QUESTION # 124
The GDPR specifies fines that may be levied against data controllers for certain infringements. Which of the following infringements would be subject to the less severe administrative fine of up to 10 million euros (or in the case of an undertaking, up to 2% of the total worldwide annual turnover of the preceding financial year)?
- A. Failure to demonstrate that consent was given by the data subject to the processing of their personal data where it is used as the basis for processing.
- B. Failure to process personal information in a manner compatible with its original purpose.
- C. Failure to provide the means for a data subject to rectify inaccuracies in personal data.
- D. Failure to implement technical and organizational measures to ensure data protection is enshrined by design and default.
Answer: D
NEW QUESTION # 125
SCENARIO
Please use the following to answer the next question:
Anna and Frank both work at Granchester University. Anna is a lawyer responsible for data protection, while Frank is a lecturer in the engineering department. The University maintains a number of types of records:
* Student records, including names, student numbers, home addresses, pre-university information, university attendance and performance records, details of special educational needs and financial information.
* Staff records, including autobiographical materials (such as curricula, professional contact files, student evaluations and other relevant teaching files).
* Alumni records, including birthplaces, years of birth, dates of matriculation and conferrals of degrees.
These records are available to former students after registering through Granchester's Alumni portal.
* Department for Education records, showing how certain demographic groups (such as first-generation students) could be expected, on average, to progress. These records do not contain names or identification numbers.
* Under their security policy, the University encrypts all of its personal data records in transit and at rest.
In order to improve his teaching, Frank wants to investigate how his engineering students perform in relational to Department for Education expectations. He has attended one of Anna's data protection training courses and knows that he should use no more personal data than necessary to accomplish his goal. He creates a program that will only export some student data: previous schools attended, grades originally obtained, grades currently obtained and first time university attended. He wants to keep the records at the individual student level. Mindful of Anna's training, Frank runs the student numbers through an algorithm to transform them into different reference numbers. He uses the same algorithm on each occasion so that he can update each record over time.
One of Anna's tasks is to complete the record of processing activities, as required by the GDPR. After receiving her email reminder, as required by the GDPR. After receiving her email reminder, Frank informs Anna about his performance database.
Ann explains to Frank that, as well as minimizing personal data, the University has to check that this new use of existing data is permissible. She also suspects that, under the GDPR, a risk analysis may have to be carried out before the data processing can take place. Anna arranges to discuss this further with Frank after she has done some additional research.
Frank wants to be able to work on his analysis in his spare time, so he transfers it to his home laptop (which is not encrypted). Unfortunately, when Frank takes the laptop into the University he loses it on the train. Frank has to see Anna that day to discuss compatible processing. He knows that he needs to report security incidents, so he decides to tell Anna about his lost laptop at the same time.
Anna will find that a risk analysis is NOT necessary in this situation as long as?
- A. The data subjects are no longer current students of Frank's
- B. The data subjects gave their unambiguous consent for the original processing
- C. The algorithms that Frank uses for the processing are technologically sound
- D. The processing will not negatively affect the rights of the data subjects
Answer: B
NEW QUESTION # 126
Which of the following demonstrates compliance with the accountability principle found in Article 5, Section 2 of the GDPR?
- A. Encrypting data in transit and at rest using strong encryption algorithms.
- B. Conducting regular audits of the data protection program.
- C. Getting consent from the data subject for a cross border data transfer.
- D. Anonymizing special categories of data.
Answer: B
NEW QUESTION # 127
......
The IAPP CIPP-E (Certified Information Privacy Professional/Europe (CIPP/E)) Certification Exam is a highly respected certification that demonstrates a deep understanding of European data protection laws and regulations. It is designed for individuals who work with the collection, use, and storage of personal information within the European Union. The exam covers a wide range of topics, such as the General Data Protection Regulation (GDPR), the ePrivacy Directive, and the EU-US Privacy Shield.
Guaranteed Success in Certified Information Privacy Professional CIPP-E Exam Dumps: https://www.itcertmagic.com/IAPP/real-CIPP-E-exam-prep-dumps.html
CIPP-E Practice Test Engine: Try These 252 Exam Questions: https://drive.google.com/open?id=1BlEfJib6zynLU-VkhVWbM3dblbtJqhki