
Verified CIPP-E dumps Q&As - 2024 Latest CIPP-E Download
Updated 100% Cover Real CIPP-E Exam Questions - 100% Pass Guarantee
IAPP CIPP/E certification exam is an essential certification for privacy professionals who work in or with organizations that operate within the EU or handle EU citizens' personal data. Certified Information Privacy Professional/Europe (CIPP/E) certification demonstrates an individual's knowledge and understanding of European data protection laws and regulations, particularly the GDPR, and is an excellent way to advance one's career in the privacy field.
What is IAPP CIPP/E Exam
IAPP has introduced Certified Information Privacy Professionals (CIPP) certificate for privacy professionals. The CIPP is the global standard for privacy professionals who manage, handle, and access data. Security professionals get a deep insight into security considerations in the European context through the European edition of CIPP which is CIPP/E.
CIPP/E is a unique designation, the only one of its kind, according to its creator the International Association of Privacy Professionals (IAPP). As a response to increasing demand for secure data privacy protection in 2014 IAPP was introduced. In all stages and throughout lifecycles these security protocols are a must. Thus the need for authoritative and certified practitioners is growing. The professionals/ candidates feel highly confident after bagging global certifications as they are able to validate there skills and abilities.
CIPP/E Exam is a certification exam that is conducted by IAPP to validates candidate knowledge and identifies technology experts that know how to build data privacy architecture from its foundation in the IT industry.
The Certified Information Privacy Professional (CIPP) helps organizations around the world support compliance and risk mitigation practices, and arms practitioners with the insight needed to add more value to their businesses.
After passing this exam, candidates get a certificate from IAPP that helps them to demonstrate their proficiency in data privacy to their clients and employers.
IAPP CIPP-E (Certified Information Privacy Professional/Europe) certification exam is a globally recognized certification for professionals who work in the field of data privacy. Certified Information Privacy Professional/Europe (CIPP/E) certification is specifically designed for individuals who work in the European market, including data protection officers, data controllers, lawyers, consultants, and other professionals who handle personal data. The CIPP-E exam covers a range of topics related to data protection laws and regulations, including the EU General Data Protection Regulation (GDPR), the EU-US Privacy Shield, and other privacy frameworks.
NEW QUESTION # 72
Which of the following countries will continue to enjoy adequacy status under the GDPR, pending any future European Commission decision to the contrary?
- A. Switzerland
- B. Norway
- C. Australia
- D. Greece
Answer: A
Explanation:
Adequacy is a term that the EU uses to describe other countries, territories, sectors or international organisations that it deems to provide an 'essentially equivalent' level of data protection to that which exists within the EU. An adequacy decision is a formal decision made by the EU which recognises that another country, territory, sector or international organisation provides an equivalent level of protection for personal data as the EU does. The effect of such a decision is that personal data can flow from the EU (and Norway, Liechtenstein and Iceland) to that third country without any further safeguard being necessary12.
The European Commission has so far recognised Andorra, Argentina, Canada (commercial organisations), Faroe Islands, Guernsey, Israel, Isle of Man, Japan, Jersey, New Zealand, Republic of Korea, Switzerland, the United Kingdom under the GDPR and the LED, the United States (commercial organisations participating in the EU-US Data Privacy Framework) and Uruguay as providing adequate protection13. On 28 June 2021, the EU Commission published two adequacy decisions in respect of the UK: one for transfers under the EU GDPR; and the other for transfers under the Law Enforcement Directive (LED)2. These decisions contain the European Commission's detailed assessment of the UK's laws and systems for protecting personal data, as well as the legislation designating the UK as adequate. Both adequacy decisions are expected to last until 27 June 20252.
Among the four options given, only Switzerland has been granted an adequacy decision by the EU, which means that it will continue to enjoy adequacy status under the GDPR, pending any future European Commission decision to the contrary. Greece is a member state of the EU, so it does not need an adequacy decision to receive personal data from the EU. Norway is a member of the European Economic Area (EEA), which also includes Iceland and Liechtenstein, and has incorporated the GDPR into its national law, so it also does not need an adequacy decision. Australia has not been recognised as adequate by the EU, so transfers of personal data from the EU to Australia require appropriate safeguards or derogations13. Therefore, the correct answer is D. Switzerland. Reference:
https://pages.iapp.org/Free-Study-Guides_CIPPE-PPC-EU.html https://data-privacy-office.eu/courses/cipp-e-official-training-course/
NEW QUESTION # 73
SCENARIO
Please use the following to answer the next question:
ProStorage is a multinational cloud storage provider headquartered in the Netherlands. Its CEO. Ruth Brown, has developed a two-pronged strategy for growth: 1) expand ProStorage s global customer base and 2) increase ProStorage's sales force by efficiently onboarding effective teams. Enacting this strategy has recently been complicated by Ruth's health condition, which has limited her working hours, as well as her ability to travel to meet potential customers. ProStorage's Human Resources department and Ruth's Chief of Staff now work together to manage her schedule and ensure that she is able to make all her medical appointments The latter has become especially crucial after Ruth's last trip to India, where she suffered a medical emergency and was hospitalized m New Delhi Unable to reach Ruths family, the hospital reached out to ProStorage and was able to connect with her Chief of Staff, who in coordination with Mary, the head of HR. provided information to the doctors based on accommodate on requests Ruth made when she started a: ProStorage Why is the additional measure recommended by Jackie sufficient foe using UpFinance?
- A. UpFinance implements sufficient data protection measures
- B. UpFinance is based in a country without surveillance laws.
- C. UpFinance is in a highly regulated financial industry
- D. UpFinance is an established 7-year-old business.
Answer: B
NEW QUESTION # 74
SCENARIO
Please use the following to answer the next question:
T-Craze, a German-headquartered specialty t-shirt company, was successfully selling to large German metropolitan cities. However, after a recent merger with another German-based company that was selling to a broader European market, T-Craze revamped its marketing efforts to sell to a wider audience. These efforts included a complete redesign of its logo to reflect the recent merger, and improvements to its website meant to capture more information about visitors through the use of cookies.
T-Craze also opened various office locations throughout Europe to help expand its business. While Germany continued to host T-Craze's headquarters and main product-design office, its French affiliate became responsible for all marketing and sales activities. The French affiliate recently procured the services of Right Target, a renowned marketing firm based in the Philippines, to run its latest marketing campaign. After thorough research, Right Target determined that T-Craze is most successful with customers between the ages of 18 and 22. Thus, its first campaign targeted university students in several European capitals, which yielded nearly 40% new customers for T-Craze in one quarter. Right Target also ran subsequent campaigns for T- Craze, though with much less success.
The last two campaigns included a wider demographic group and resulted in countless unsubscribe requests, including a large number in Spain. In fact, the Spanish data protection authority received a complaint from Sofia, a mid-career investment banker. Sofia was upset after receiving a marketing communication even after unsubscribing from such communications from the Right Target on behalf of T-Craze.
Which of the following is T-Craze's lead supervisory authority?
- A. Spain, because that is T-Craze's primary market based on its marketing campaigns.
- B. France, because that is where T-Craze conducts processing of personal information.
- C. T-Craze may choose its lead supervisory authority where any of its affiliates are based, because it has presence in several European countries.
- D. Germany, because that is where T-Craze is headquartered.
Answer: A
NEW QUESTION # 75
Which of the following Convention 108+ principles, as amended in 2018, is NOT consistent with a principle found in the GDPR?
- A. The necessity of the bulk collection of personal data by the government.
- B. The requirement to demonstrate compliance to a supervisory authority.
- C. The obligation of companies to declare data breaches.
Answer: A
Explanation:
The Convention 108+ is the modernized version of the Council of Europe Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data, which was opened for signature on 10 October 20181. The Convention 108+ aims to reinforce the individuals' protection, strengthen the implementation of the Convention, and promote it as a universal standard for data protection2. The Convention 108+ reflects the same principles as those enshrined in the EU's General Data Protection Regulation (GDPR), which applies from 25 May 20183. Therefore, the Convention 108+ and the GDPR are largely consistent and coherent in their provisions and objectives.
However, one of the principles of the Convention 108+ that is not consistent with a principle found in the GDPR is the necessity of the bulk collection of personal data by the government. The Convention 108+ allows for the possibility of bulk collection of personal data by the government for national security purposes, subject to certain safeguards and oversight mechanisms. The GDPR, on the other hand, does not regulate the processing of personal data by the government for national security purposes, as this falls outside the scope of EU law. The GDPR also does not explicitly endorse the bulk collection of personal data by the government, but rather requires that any processing of personal data must be based on a legal basis, respect the principles of data protection, and ensure the rights and freedoms of data subjects. Therefore, the correct answer is C.
Reference:
Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data Convention 108+ and the GDPR General Data Protection Regulation
[Convention 108+: the consultative committee of the convention for the protection of individuals with regard to the processing of personal data (T-PD) publishes its guidelines on artificial intelligence and data protection]
[Article 3 GDPR - Territorial scope]
[Article 5 GDPR - Principles relating to processing of personal data]
I hope this helps you understand the Convention 108+ and the GDPR better. If you have any other questions, please feel free to ask me.
NEW QUESTION # 76
Assuming that the "without undue delay" provision is followed, what is the time limit for complying with a data access request?
- A. Within one month of receipt, which may be extended by up to an additional month
- B. Within one month of receipt, which may be extended by an additional two months
- C. Within 40 days of receipt
- D. Within 40 days of receipt, which may be extended by up to 40 additional days
Answer: A
Explanation:
Reference https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection- regulation-gdpr/individual-rights/right-of-access/
NEW QUESTION # 77
Which of the following is NOT a role of works councils?
- A. Determining what changes will affect employee working conditions.
- B. Determining the monetary fines to be levied against employers for data breach violations of employee data.
- C. Determining whether employees' personal data can be processed or not.
- D. Determining whether to approve or reject certain decisions of the employer that affect employees.
Answer: B
Explanation:
Works councils are employee representative bodies that exist in some European countries, such as Germany, France, Spain and Italy. They have various roles and powers depending on the national laws and collective agreements, but generally they aim to protect and promote the interests of the employees in relation to the employer. Some of the common roles of works councils are:
Determining whether to approve or reject certain decisions of the employer that affect employees, such as transfers, dismissals, redundancies, working hours, health and safety, etc.
Determining whether employees' personal data can be processed or not, based on the principle of co-determination, which means that the employer needs the consent of the works council for any data processing that involves employee monitoring, evaluation or control.
Determining what changes will affect employee working conditions, such as wages, benefits, training, social facilities, etc.
However, works councils do not have the role of determining the monetary fines to be levied against employers for data breach violations of employee data. This is the role of the data protection authorities, which are independent public bodies that supervise, through investigative and corrective powers, the application of the data protection law. Works councils may cooperate with the data protection authorities or file complaints on behalf of the employees, but they do not have the authority to impose sanctions on the employers. Reference: Free CIPP/E Study Guide, page 27; CIPP/E Certification, page 13.
NEW QUESTION # 78
Under what circumstances would the GDPR apply to personal data that exists in physical form, such as information contained in notebooks or hard copy files?
- A. Only where the personal data is to be subjected to specific computerized processing, such as image scanning or optical character recognition.
- B. Only where the personal data is treated by automated means in some way, such as computerized distribution or filing.
- C. Only where the personal data is handled in a sufficiently structured manner so as to form part of a filing system.
- D. Only where the personal data is produced as a physical output of specific automated processing activities, such as printing, labelling, or stamping.
Answer: C
NEW QUESTION # 79
SCENARIO
Please use the following to answer the next question:
Jane Stan's her new role as a Data Protection Officer (DPO) at a Malta-based company that allows anyone to buy and sell cryptocurrencies via its online platform. The company stores and processes the personal data of its customers in a dedicated data center located in Malta (EU).
People wishing to trade cryptocurrencies are required to open an online account on the platform. They then must successfully pass a KYC due diligence procedure aimed at preventing money laundering and ensuring compliance with applicable financial regulations.
The non-European customers are also required to waive all their GDPR rights by reading a disclaimer written in bold and belong a checkbox on a separate page in order to get their account approved on the platform.
The customers must likewise accept the terms of service of the platform. The terms of service also include a privacy policy section, saying, among other things, that if a Are the cybersecurity assessors required to sign a data processing agreement with the company in order to comply with the GDPR''
- A. Yes. the assessors a-e considered to be joint data controllers and must sign a mutual data processing agreement.
- B. Yes, the assessors are data processors and their processing of personal data must be governed by a separate contract or other legal act.
- C. No. the assessors do not quality as data processors as they do not copy the data to their facilities.
- D. No, the assessors do not quality as data processors as they only have access to encrypted data.
Answer: B
NEW QUESTION # 80
SCENARIO
Please use the following to answer the next question:
TripBliss Inc. is a travel service company which has lost substantial revenue over the last few years. Their new manager, Oliver, suspects that this is partly due to the company's outdated website. After doing some research, he meets with a sales representative from the up-and-coming IT company Techiva, hoping that they can design a new, cutting-edge website for TripBliss Inc.'s foundering business.
During negotiations, a Techiva representative describes a plan for gathering more customer information through detailed Questionaires, which could be used to tailor their preferences to specific travel destinations. TripBliss Inc. can choose any number of data categories - age, income, ethnicity - that would help them best accomplish their goals. Oliver loves this idea, but would also like to have some way of gauging how successful this approach is, especially since the Questionaires will require customers to provide explicit consent to having their data collected. The Techiva representative suggests that they also run a program to analyze the new website's traffic, in order to get a better understanding of how customers are using it. He explains his plan to place a number of cookies on customer devices. The cookies will allow the company to collect IP addresses and other information, such as the sites from which the customers came, how much time they spend on the TripBliss Inc. website, and which pages on the site they visit. All of this information will be compiled in log files, which Techiva will analyze by means of a special program. TripBliss Inc. would receive aggregate statistics to help them evaluate the website's effectiveness. Oliver enthusiastically engages Techiva for these services.
Techiva assigns the analytics portion of the project to longtime account manager Leon Santos. As is standard practice, Leon is given administrator rights to TripBliss Inc.'s website, and can authorize access to the log files gathered from it. Unfortunately for TripBliss Inc., however, Leon is taking on this new project at a time when his dissatisfaction with Techiva is at a high point. In order to take revenge for what he feels has been unfair treatment at the hands of the company, Leon asks his friend Fred, a hobby hacker, for help. Together they come up with the following plan: Fred will hack into Techiva's system and copy their log files onto a USB stick. Despite his initial intention to send the USB to the press and to the data protection authority in order to denounce Techiva, Leon experiences a crisis of conscience and ends up reconsidering his plan. He decides instead to securely wipe all the data from the USB stick and inform his manager that the company's system of access control must be reconsidered.
After Leon has informed his manager, what is Techiva's legal responsibility as a processor?
- A. They must report it to TripBliss Inc.
- B. They must conduct a full systems audit.
- C. They must inform customers who have used the website.
- D. They must report it to the supervisory authority.
Answer: B
NEW QUESTION # 81
How does the GDPR now define "processing"?
- A. Any use or disclosure of personal data compatible with the purpose for which the data was collected.
- B. Any act involving the collecting and recording of personal data.
- C. Any operation or set of operations performed on personal data or on sets of personal data.
- D. Any operation or set of operations performed by automated means on personal data or on sets of personal data.
Answer: B
NEW QUESTION # 82
What type of data lies beyond the scope of the General Data Protection Regulation?
- A. Masked
- B. Pseudonymized
- C. Encrypted
- D. Anonymized
Answer: D
Explanation:
The General Data Protection Regulation (GDPR) is a data protection law that applies to the processing of personal data of individuals in the European Union (EU) and the European Economic Area (EEA). Personal data is any information relating to an identified or identifiable natural person, such as name, address, email, phone number, etc12. The GDPR does not apply to personal data that is anonymized, meaning that it cannot be linked back to a specific individual12. Anonymization can be achieved by removing or masking any identifying information from the data, such as using pseudonyms, aggregating or generalizing the data, or applying statistical methods12.
Therefore, the type of data that lies beyond the scope of the GDPR is anonymized data.
Reference:
https://commission.europa.eu/law/law-topic/data-protection/reform/what-personal-data_en#:~:text=Different%20pieces%20of%20information%2C%20which,the%20scope%20of%20the%20GDPR. B. ANONYMIZED Personal data is any information that relates to an identified or identifiable living individual. Different pieces of information, which collected together can lead to the identification of a particular person, also constitute personal data. Personal data that has been de-identified, encrypted or pseudonymised but can be used to re-identify a person remains personal data and falls within the scope of the GDPR. Personal data that has been rendered anonymous in such a way that the individual is not or no longer identifiable is no longer considered personal data. For data to be truly anonymised, the anonymisation must be irreversible.
NEW QUESTION # 83
A U.S.-based online shop uses sophisticated software to track the browsing behavior of its European customers and predict future purchases. It also shares this information with third parties. Under the GDPR, what is the online shop's PRIMARY obligation while engaging in this kind of profiling?
- A. It must prove that it uses sufficient security safeguards to protect customer data
- B. It must be able to demonstrate a prior business relationship with the customers
- C. It must solicit informed consent through a notice on its website
- D. It must seek authorization from the European supervisory authorities
Answer: C
NEW QUESTION # 84
Which change was introduced by the 2009 amendments to the e-Privacy Directive 2002/58/EC?
- A. A voluntary notification for personal data breaches applicable to all data controllers.
- B. A mandatory notification for personal data breaches applicable to all data controllers.
- C. A voluntary notification for personal data breaches applicable to electronic communication providers.
- D. A mandatory notification for personal data breaches applicable to electronic communication providers.
Answer: D
Explanation:
Reference https://eur-lex.europa.eu/legal-content/EN/ALL/?uri=CELEX:32009L0136
NEW QUESTION # 85
SCENARIO
Please use the following to answer the next question:
T-Craze, a German-headquartered specialty t-shirt company, was successfully selling to large German metropolitan cities. However, after a recent merger with another German-based company that was selling to a broader European market, T-Craze revamped its marketing efforts to sell to a wider audience. These efforts included a complete redesign of its logo to reflect the recent merger, and improvements to its website meant to capture more information about visitors through the use of cookies.
T-Craze also opened various office locations throughout Europe to help expand its business. While Germany Target, a renowned marketing firm based in the Philippines, to run its latest marketing campaign. After thorough research, Right Target determined that T-Craze is most successful with customers between the ages of 18 and 22. Thus, its first campaign targeted university students in several European capitals, which yielded nearly 40% new customers for T-Craze in one quarter. Right Target also ran subsequent campaigns for T- Craze, though with much less success.
The last two campaigns included a wider demographic group and resulted in countless unsubscribe requests, including a large number in Spain. In fact, the Spanish data protection authority received a complaint from Sofia, a mid-career investment banker. Sofia was upset after receiving a marketing communication even after unsubscribing from such communications from the Right Target on behalf of T-Craze.
What is the best option for the lead regulator when responding to the Spanish supervisory authority's notice that it plans to take action regarding Sofia's complaint?
- A. Reject, because Right Target's processing was conducted throughout Europe.
- B. Accept, because GDPR permits non-lead authorities to take action for such complaints.
- C. Reject, because GDPR does not allow other supervisory authorities to take action if there is a lead authority.
- D. Accept, because it did not receive any complaints.
Answer: C
NEW QUESTION # 86
In the Planet 49 case, what was the man judgement of the Coon of Justice of the European Union (CJEU) regarding the issue of cookies?
- A. If a data subject continues to scroll through a website after reading a cookie banner, this activity constitutes valid consent for the tracking described in the cookie banner.
- B. If the ePrivacy Directive requires consent for cookies, then the GDPR's consent requirements apply.
- C. If the cookies do not track personal data, then pre-checked boxes are acceptable.
- D. If a website's cookie notice makes clear the information gathered and the lifespan of the cookie, then pre-checked boxes are acceptable.
Answer: A
NEW QUESTION # 87
Select the answer below that accurately completes the following:
"The right to compensation and liability under the GDPR...
- A. ...provides for an exemption from liability if the data controller (or data processor) proves that it is not in any way responsible for the event giving rise to the damage."
- B. ...precludes any subsequent recourse proceedings against other controllers or processors involved in the same processing."
- C. ...is limited to a maximum amount of EUR 20 million per event of damage or loss."
- D. ...can only be exercised against the data controller, even if a data processor was involved in the same processing."
Answer: B
Explanation:
Reference https://gdpr-info.eu/art-82-gdpr/
NEW QUESTION # 88
SCENARIO
Please use the following to answer the next question:
Brady is a computer programmer based in New Zealand who has been running his own business for two years. Brady's business provides a low-cost suite of services to customers throughout the European Economic Area (EEA). The services are targeted towards new and aspiring small business owners. Brady's company, called Brady Box, provides web page design services, a Social Networking Service (SNS) and consulting services that help people manage their own online stores.
Unfortunately, Brady has been receiving some complaints. A customer named Anna recently uploaded her plans for a new product onto Brady Box's chat area, which is open to public viewing. Although she realized her mistake two weeks later and removed the document, Anna is holding Brady Box responsible for not noticing the error through regular monitoring of the website. Brady believes he should not be held liable.
Another customer, Felipe, was alarmed to discover that his personal information was transferred to a third- party contractor called Hermes Designs and worries that sensitive information regarding his business plans may be misused. Brady does not believe he violated European privacy rules. He provides a privacy notice to all of his customers explicitly stating that personal data may be transferred to specific third parties in fulfillment of a requested service. Felipe says he read the privacy notice but that it was long and complicated Brady continues to insist that Felipe has no need to be concerned, as he can personally vouch for the integrity of Hermes Designs. In fact, Hermes Designs has taken the initiative to create sample customized banner advertisements for customers like Felipe. Brady is happy to provide a link to the example banner ads, now posted on the Hermes Designs webpage. Hermes Designs plans on following up with direct marketing to these customers.
Brady was surprised when another customer, Serge, expressed his dismay that a quotation by him is being used within a graphic collage on Brady Box's home webpage. The quotation is attributed to Serge by first and last name. Brady, however, was not worried about any sort of litigation. He wrote back to Serge to let him know that he found the quotation within Brady Box's Social Networking Service (SNS), as Serge himself had posted the quotation. In his response, Brady did offer to remove the quotation as a courtesy.
Despite some customer complaints, Brady's business is flourishing. He even supplements his income through online behavioral advertising (OBA) via a third-party ad network with whom he has set clearly defined roles. Brady is pleased that, although some customers are not explicitly aware of the OBA, the advertisements contain useful products and services.
Under the General Data Protection Regulation (GDPR), what is the most likely reason Serge may have grounds to object to the use of his quotation?
- A. Because of the misrepresentation of personal data as an endorsement.
- B. Because of the juxtaposition of the quotation with others' quotations.
- C. Because of the misapplication of the household exception in relation to a social networking service (SNS).
- D. Because of the use of personal data outside of the social networking service (SNS).
Answer: D
Explanation:
The GDPR defines personal data as "any information relating to an identified or identifiable natural person" (Article 4(1)). This includes names, quotations, and any other data that can be linked to a specific individual. The GDPR also requires that personal data be processed lawfully, fairly, and transparently, and that it be collected for specified, explicit, and legitimate purposes (Article 5(1)). Furthermore, the GDPR grants data subjects the right to object to the processing of their personal data for direct marketing purposes or for the purposes of the legitimate interests of the controller or a third party (Article 21).
In this scenario, Serge may have grounds to object to the use of his quotation on Brady Box's home webpage, as it constitutes the processing of his personal data outside of the original purpose for which it was collected. Serge posted the quotation on Brady Box's SNS, which is a separate service from Brady Box's web page design service. By using the quotation on the home webpage, Brady Box is processing Serge's personal data for a different purpose than the one for which Serge provided it, and without his consent or a legitimate interest. This may violate the principles of purpose limitation and lawfulness under the GDPR. Moreover, Serge may object to the use of his quotation as it implies his endorsement of Brady Box's service, which may affect his reputation or interests.
The other options are less likely to be valid grounds for objection, as they are not directly related to the GDPR's provisions on personal data protection. The misrepresentation of personal data as an endorsement may be a matter of contract law or consumer protection law, but not necessarily a GDPR issue. The juxtaposition of the quotation with others' quotations may not affect Serge's rights or interests, unless it creates a false or misleading impression of his views or opinions. The misapplication of the household exception in relation to a SNS may not apply in this case, as the household exception only covers the processing of personal data by a natural person in the course of a purely personal or household activity (Article 2(2)). Serge's posting of the quotation on a SNS may not qualify as a purely personal or household activity, as it involves the disclosure of personal data to a wider audience.
Reference:
GDPR
GDPR and social media
How does GDPR affect social media marketing?
Data Protection & Social Media: How GDPR Influences Today's Social Media Marketing
NEW QUESTION # 89
Under which of the following conditions does the General Data Protection Regulation NOT apply to the processing of personal data?
- A. When the personal data is held by the controller but not processed for further purposes
- B. When the personal data is processed by an individual only for their household activities
- C. When the personal data is collected and then pseudonymised by the controller
- D. When the personal data is processed only in non-electronic form
Answer: C
NEW QUESTION # 90
A key component of the OECD Guidelines is the "Individual Participation Principle". What parts of the General Data Protection Regulation (GDPR) provide the closest equivalent to that principle?
- A. The information requirements set out in Articles 13 and 14
- B. The breach notification requirements specified in Articles 33 and 34
- C. The rights granted to data subjects under Articles 12 to 22
- D. The lawful processing criteria stipulated by Articles 6 to 9
Answer: C
NEW QUESTION # 91
Based on GDPR Article 35, which of the following situations would trigger the need to complete a DPIA?
- A. A company wants to build a dating app that creates candidate profiles based on location data and data from third-party sources.
- B. A company wants to use location data to infer information on a person's clothes purchasing habits.
- C. A company wants to use location data to track delivery trucks in order to make the routes more efficient.
- D. A company wants to combine location data with other data in order to offer more personalized service for the customer.
Answer: A
NEW QUESTION # 92
SCENARIO
Please use the following to answer the next question:
You have just been hired by a toy manufacturer based in Hong Kong. The company sells a broad range of dolls, action figures and plush toys that can be found internationally in a wide variety of retail stores. Although the manufacturer has no offices outside Hong Kong and in fact does not employ any staff outside Hong Kong, it has entered into a number of local distribution contracts. The toys produced by the company can be found in all popular toy stores throughout Europe, the United States and Asia. A large portion of the company's revenue is due to international sales.
The company now wishes to launch a new range of connected toys, ones that can talk and interact with children. The CEO of the company is touting these toys as the next big thing, due to the increased possibilities offered: The figures can answer children's questions on various subjects, such as mathematical calculations or the weather. Each figure is equipped with a microphone and speaker and can connect to any smartphone or tablet via Bluetooth. Any mobile device within a 10-meter radius can connect to the toys via Bluetooth as well.
The figures can also be associated with other figures (from the same manufacturer) and interact with each other for an enhanced play experience.
When a child asks the toy a question, the request is sent to the cloud for analysis, and the answer is generated on cloud servers and sent back to the figure. The answer is given through the figure's integrated speakers, making it appear as though that the toy is actually responding to the child's question. The packaging of the toy does not provide technical details on how this works, nor does it mention that this feature requires an internet connection. The necessary data processing for this has been outsourced to a data center located in South Africa. However, your company has not yet revised its consumer-facing privacy policy to indicate this.
In parallel, the company is planning to introduce a new range of game systems through which consumers can play the characters they acquire in the course of playing the game. The system will come bundled with a portal that includes a Near-Field Communications (NFC) reader. This device will read an RFID tag in the action figure, making the figure come to life onscreen. Each character has its own stock features and abilities, but it is also possible to earn additional ones by accomplishing game goals. The only information stored in the tag relates to the figures' abilities. It is easy to switch characters during the game, and it is possible to bring the figure to locations outside of the home and have the character's abilities remain intact.
In light of the requirements of Article 32 of the GDPR (related to the Security of Processing), which practice should the company institute?
- A. Include dual-factor authentication before each use by a child in order to ensure a minimum amount of security.
- B. Encrypt the data in transit over the wireless Bluetooth connection.
- C. Include three-factor authentication before each use by a child in order to ensure the best level of security possible.
- D. Insert contractual clauses into the contract between the toy manufacturer and the cloud service provider, since South Africa is outside the European Union.
Answer: B
NEW QUESTION # 93
Which area of privacy is a lead supervisory authority's (LSA) MAIN concern?
- A. Cross-border processing
- B. Special categories of data
- C. Data subject rights
- D. Data access disputes
Answer: A
Explanation:
A lead supervisory authority (LSA) is the main point of contact for organisations that process personal data across multiple EU member states. The LSA is responsible for coordinating cross-border investigations, issuing binding decisions, and enforcing GDPR compliance1. Cross-border processing is the main concern of the LSA, as it involves data processing activities that affect data subjects in more than one member state, or that take place in more than one member state2. The other options are not the main concern of the LSA, as they are either covered by the national supervisory authorities of each member state, or are not specific to cross-border processing. Reference: Is it possible to choose your lead supervisory authority under the GDPR?, Art. 56 GDPR - Competence of the lead supervisory authority, Navigating GDPR Compliance with a Lead Supervisory Authority, Guidelines 8/2022 on identifying a controller or processor's lead supervisory authority
NEW QUESTION # 94
As a Data Protection Officer for a small bank in the European Union, you receive a data subject access request from one of your customers. The customer provides you with his name, and has used the email address registered in your system.
What would be the most appropriate way to confirm the identity of the customer?
- A. Request that the customer provide his bank account number.
- B. Request that the customer answer additional security questions.
- C. Request a copy of the customer's government-issued ID document.
- D. Request a copy of the customer's last bank account statement.
Answer: B
Explanation:
According to the CIPP/E study guide, data controllers should use the least intrusive means of verifying the identity of data subjects who make requests under the GDPR. Asking for a copy of an ID document or a bank account statement may be disproportionate and excessive, as they contain more personal data than necessary for authentication. Asking for the bank account number may not be sufficient, as it may be easily obtained by third parties. Therefore, the most appropriate way to confirm the identity of the customer is to ask additional security questions that only the customer would know, such as the date of the last transaction, the amount of the last deposit, or the name of the beneficiary of a recurring payment.
NEW QUESTION # 95
Higher fines are assessed for GDPR violations due to which of the following?
- A. Violations of a data controller's obligations to obtain a child's consent
- B. Failure to notify a supervisory authority and data subjects of a personal data breach
- C. Failure to appoint a data protection officer.
- D. Violations of a data subject"s rights
Answer: A
NEW QUESTION # 96
......
Use Real Dumps - 100% Free CIPP-E Exam Dumps: https://www.itcertmagic.com/IAPP/real-CIPP-E-exam-prep-dumps.html
Realistic CIPP-E Dumps Latest Practice Tests Dumps: https://drive.google.com/open?id=1wJYxZ5rHUnHyHvFyD8DIqgRACdfeLhel