2024 Free IAPP CIPP-E Exam Files Downloaded Instantly [Q131-Q151]

Share

2024 Free IAPP CIPP-E Exam Files Downloaded Instantly

Pass IAPP CIPP-E exam Dumps 100 Pass Guarantee With Latest Demo


The CIPP-E exam is a rigorous test that requires a comprehensive understanding of the legal, regulatory, and ethical issues surrounding data protection in Europe. CIPP-E exam covers key topics such as the rights of data subjects, data protection impact assessments, and international data transfers. Successful completion of the CIPP-E exam demonstrates an individual's commitment to privacy and data protection, making them a valuable asset to any organization looking to achieve compliance with European data protection laws.


The CIPP-E certification is particularly relevant for professionals who work with personal data and are responsible for ensuring compliance with the General Data Protection Regulation (GDPR). GDPR is a regulation that came into effect in May 2018 and is applicable to all organizations that process personal data of EU citizens, regardless of where the organization is located. The regulation has a significant impact on how personal data is collected, processed, stored, and secured, and failure to comply with GDPR can result in severe penalties.

 

NEW QUESTION # 131
A mobile device application that uses cookies will be subject to the consent requirement of which of the following?

  • A. The EU Cybersecurity Directive
  • B. The ePrivacy Directive
  • C. The Data Retention Directive
  • D. The E-Commerce Directive

Answer: B


NEW QUESTION # 132
Which of the following is NOT a role of works councils?

  • A. Determining whether employees' personal data can be processed or not.
  • B. Determining whether to approve or reject certain decisions of the employer that affect employees.
  • C. Determining the monetary fines to be levied against employers for data breach violations of employee data.
  • D. Determining what changes will affect employee working conditions.

Answer: C

Explanation:
Works councils are employee representative bodies that exist in some European countries, such as Germany, France, Spain and Italy. They have various roles and powers depending on the national laws and collective agreements, but generally they aim to protect and promote the interests of the employees in relation to the employer. Some of the common roles of works councils are:
Determining whether to approve or reject certain decisions of the employer that affect employees, such as transfers, dismissals, redundancies, working hours, health and safety, etc.
Determining whether employees' personal data can be processed or not, based on the principle of co-determination, which means that the employer needs the consent of the works council for any data processing that involves employee monitoring, evaluation or control.
Determining what changes will affect employee working conditions, such as wages, benefits, training, social facilities, etc.
However, works councils do not have the role of determining the monetary fines to be levied against employers for data breach violations of employee data. This is the role of the data protection authorities, which are independent public bodies that supervise, through investigative and corrective powers, the application of the data protection law. Works councils may cooperate with the data protection authorities or file complaints on behalf of the employees, but they do not have the authority to impose sanctions on the employers. Reference: Free CIPP/E Study Guide, page 27; CIPP/E Certification, page 13.


NEW QUESTION # 133
An online company's privacy practices vary due to the fact that it offers a wide variety of services. How could it best address the concern that explaining them all would make the policies incomprehensible?

  • A. Use a layered privacy notice on its website and in its email communications.
  • B. Provide only general information about its processing activities and offer a toll-free number for more information.
  • C. Place a banner on its website stipulating that visitors agree to its privacy policy and terms of use by visiting the site.
  • D. Identify uses of data in a privacy notice mailed to the data subject.

Answer: D


NEW QUESTION # 134
A company has collected personal data tor direct marketing purpose on the basis of consent. It is now considering using this data to develop new products through analytics. What is the company first required to do?

  • A. Obtain specific consent for the new processing
  • B. Only inform the data subjects of the new purpose.
  • C. Update the privacy notice upon which consent was given
  • D. Proceed no further, as such repurposing is unlawful

Answer: A

Explanation:
According to the GDPR, consent is one of the lawful bases for processing personal data1. Consent means any freely given, specific, informed and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her2. Therefore, consent must be specific to each purpose of processing and cannot be bundled with other purposes3. If a company wants to use personal data for a new purpose that is not compatible with the original purpose for which consent was given, it must obtain a new consent from the data subjects for the new processing4. Simply informing the data subjects of the new purpose or updating the privacy notice is not sufficient, as it does not imply the data subject's agreement to the new processing. Proceeding with the new processing without obtaining a new consent would be unlawful and could result in fines and sanctions5. Reference:
Free CIPP/E Study Guide, page 23, section 4.1.1
GDPR, Article 4 (11)
GDPR, Recital 32
GDPR, Article 6 (4)
GDPR, Article 83 (5) (a)


NEW QUESTION # 135
After detecting an intrusion involving the theft of unencrypted personal data, who shall the breached company notify first under GDPR requirements?

  • A. A competent supervisory authority.
  • B. Any parents of children whose personal data was compromised.
  • C. Any affected customers whose data was compromised.
  • D. A local law enforcement agency

Answer: C


NEW QUESTION # 136
When hiring a data processor, which action would a data controller NOT be able to depend upon to avoid liability in the event of a security breach?

  • A. Conducting a risk assessment to analyze possible outsourcing threats.
  • B. Maintaining evidence that the processor was the best possible market choice available.
  • C. Requiring that the processor directly notify the appropriate supervisory authority.
  • D. Documenting due diligence steps taken in the pre-contractual stage.

Answer: D


NEW QUESTION # 137
SCENARIO
Please use the following to answer the next question:
Due to rapidly expanding workforce, Company A has decided to outsource its payroll function to Company B. Company B is an established payroll service provider with a sizable client base and a solid reputation in the industry.
Company B's payroll solution for Company A relies on the collection of time and attendance data obtained via a biometric entry system installed in each of Company A's factories. Company B won't hold any biometric data itself, but the related data will be uploaded to Company B's UK servers and used to provide the payroll service. Company B's live systems will contain the following information for each of Company A's employees:
Name
Address
Date of Birth
Payroll number
National Insurance number
Sick pay entitlement
Maternity/paternity pay entitlement
Holiday entitlement
Pension and benefits contributions
Trade union contributions
Jenny is the compliance officer at Company A. She first considers whether Company A needs to carry out a data protection impact assessment in relation to the new time and attendance system, but isn't sure whether or not this is required.
Jenny does know, however, that under the GDPR there must be a formal written agreement requiring Company B to use the time and attendance data only for the purpose of providing the payroll service, and to apply appropriate technical and organizational security measures for safeguarding the data. Jenny suggests that Company B obtain advice from its data protection officer. The company doesn't have a DPO but agrees, in the interest of finalizing the contract, to sign up for the provisions in full. Company A enters into the contract.
Weeks later, while still under contract with Company A, Company B embarks upon a separate project meant to enhance the functionality of its payroll service, and engages Company C to help. Company C agrees to extract all personal data from Company B's live systems in order to create a new database for Company B.
This database will be stored in a test environment hosted on Company C's U.S. server. The two companies agree not to include any data processing provisions in their services agreement, as data is only being used for IT testing purposes.
Unfortunately, Company C's U.S. server is only protected by an outdated IT security system, and suffers a cyber security incident soon after Company C begins work on the project. As a result, data relating to Company A's employees is visible to anyone visiting Company C's website. Company A is unaware of this until Jenny receives a letter from the supervisory authority in connection with the investigation that ensues. As soon as Jenny is made aware of the breach, she notifies all affected employees.
Under the GDPR, which of Company B's actions would NOT be likely to trigger a potential enforcement action?

  • A. Their failure to provide sufficient security safeguards to Company A's data.
  • B. Their decision to operate without a data protection officer.
  • C. Their omission of data protection provisions in their contract with Company C.
  • D. Their engagement of Company C to improve their payroll service.

Answer: D

Explanation:
While Company B made several mistakes in handling Company A's employee data, not all of them would likely trigger a potential enforcement action under the GDPR. Here's an analysis of each option:
A) Omission of data protection provisions in the contract with Company C: This is a clear violation of the GDPR. Company B, as the data controller, is responsible for ensuring that any third-party processors comply with data protection requirements. By omitting data protection provisions in the contract, Company B failed to take appropriate steps to ensure the security and privacy of the personal data. This would be a likely trigger for an enforcement action.
B) Failure to provide sufficient security safeguards to Company A's data: This is another violation of the GDPR. Company B has a legal obligation to implement appropriate technical and organizational security measures to protect personal data from unauthorized access, use, disclosure, alteration, or destruction. The outdated IT security system at Company C's U.S. server demonstrates a failure to meet this obligation. This would also be a likely trigger for an enforcement action.
C) Engagement of Company C to improve their payroll service: While outsourcing certain aspects of data processing is permitted under the GDPR, the data controller remains ultimately responsible for compliance. However, simply engaging another company to improve a service itself isn't necessarily a violation. As long as the proper safeguards are in place and the data processing is carried out in accordance with the GDPR, this action alone would not likely trigger an enforcement action.
D) Decision to operate without a data protection officer: The GDPR requires certain organizations to appoint a data protection officer (DPO). While Company B may be required to have a DPO depending on its size and activities, the absence of a DPO wouldn't automatically trigger an enforcement action. However, it could indicate a lack of compliance culture and contribute to other violations, increasing the likelihood of an enforcement action.
Therefore, while Company B made several mistakes, only the ones that directly violate specific data protection requirements, such as omitting data protection provisions in contracts or failing to implement appropriate security measures, are likely to trigger an enforcement action. Engaging a third-party to improve a service, as long as it's done in a compliant manner, isn't a violation in itself.


NEW QUESTION # 138
SCENARIO
Please use the following to answer the next question:
Joe started the Gummy Bear Company in 2000 from his home in Vermont, USA. Today, it is a multi-billion-dollar candy company operating in every continent. All of the company's IT servers are located in Vermont. This year Joe hires his son Ben to join the company and head up Project Big, which is a major marketing strategy to triple gross revenue in just 5 years. Ben graduated with a PhD in computer software from a top university. Ben decided to join his father's company, but is also secretly working on launching a new global online dating website company called Ben Knows Best.
Ben is aware that the Gummy Bear Company has millions of customers and believes that many of them might also be interested in finding their perfect match. For Project Big, Ben redesigns the company's online web portal and requires customers in the European Union and elsewhere to provide additional personal information in order to remain a customer. Project Ben begins collecting data about customers' philosophical beliefs, political opinions and marital status.
If a customer identifies as single, Ben then copies all of that customer's personal data onto a separate database for Ben Knows Best. Ben believes that he is not doing anything wrong, because he explicitly asks each customer to give their consent by requiring them to check a box before accepting their information. As Project Big is an important project, the company also hires a first year college student named Sam, who is studying computer science to help Ben out.
Ben calls out and Sam comes across the Ben Knows Best database. Sam is planning on going to Ireland over Spring Beak with 10 of his friends, so he copies all of the customer information of people that reside in Ireland so that he and his friends can contact people when they are in Ireland.
Joe also hires his best friend's daughter, Alice, who just graduated from law school in the U.S., to be the company's new General Counsel. Alice has heard about the GDPR, so she does some research on it. Alice approaches Joe and informs him that she has drafted up Binding Corporate Rules for everyone in the company to follow, as it is important for the company to have in place a legal mechanism to transfer data internally from the company's operations in the European Union to the U.S.
Joe believes that Alice is doing a great job, and informs her that she will also be in-charge of handling a major lawsuit that has been brought against the company in federal court in the U.S. To prepare for the lawsuit, Alice instructs the company's IT department to make copies of the computer hard drives from the entire global sales team, including the European Union, and send everything to her so that she can review everyone's information. Alice believes that Joe will be happy that she did the first level review, as it will save the company a lot of money that would otherwise be paid to its outside law firm.
Ben's collection of additional data from customers created several potential issues for the company, which would most likely require what?

  • A. Hiring a data protection officer.
  • B. New corporate governance and code of conduct.
  • C. A comprehensive data inventory.
  • D. A data protection impact assessment.

Answer: D

Explanation:
Ben's collection of additional data from customers, especially sensitive data such as philosophical beliefs and political opinions, created several potential issues for the company, such as:
The risk of violating the data minimization principle, which requires that personal data collected must be adequate, relevant and limited to what is necessary for the purposes of the processing1.
The risk of infringing the rights and freedoms of the data subjects, who may not be aware of or consent to the secondary use of their data by Ben Knows Best, or the unauthorized access and copying of their data by Sam.
The risk of non-compliance with the GDPR's requirements for processing special categories of data, which include data revealing philosophical beliefs and political opinions. Such data can only be processed under certain conditions, such as explicit consent, substantial public interest, or legal claims2.
The risk of data breaches or losses, as the data is transferred to a separate database, copied by Sam, and stored on the company's servers in Vermont, which may not have adequate security measures or safeguards.
Therefore, the company would most likely require a data protection impact assessment (DPIA) to identify and mitigate these risks. A DPIA is a process that helps assess the impact of the envisaged processing operations on the protection of personal data, and consult with the supervisory authority if the DPIA indicates that the processing would result in a high risk in the absence of measures taken by the controller to mitigate the risk3. The other options are not necessarily required by the GDPR, although they may be good practices or contractual terms. Reference:
Free CIPP/E Study Guide, page 32, section 4.1.2
CIPP/E Certification, page 27, section 4.1.2
The Ultimate CIPP/E Study Guide for 2023, page 36, section 4.1.2
Principles - General Data Protection Regulation (GDPR), Article 5
Special categories of personal data - General Data Protection Regulation (GDPR), Article 9 Data protection impact assessment - General Data Protection Regulation (GDPR), Article 35


NEW QUESTION # 139
When does the GDPR provide more latitude for a company to process data beyond its original collection purpose?

  • A. When the data serves legitimate interest of third parties.
  • B. When the data has been pseudonymized.
  • C. When the data subject has failed to use a provided opt-out mechanism.
  • D. When the data is protected by technological safeguards.

Answer: A

Explanation:
Section: (none)


NEW QUESTION # 140
When is data sharing agreement MOST likely to be needed?

  • A. When personal data is being proactively shared by a controller to support a police investigation.
  • B. When anonymized data is being shared.
  • C. When personal data is being shared between commercial organizations acting as joint data controllers.
  • D. When personal data is being shared with a public authority with powers to require the personal data to be disclosed.

Answer: C

Explanation:
A data sharing agreement is a contract that documents what data is being shared and how it can be used. It can be used to make data sharing lawful and to demonstrate compliance with the accountability principle under the GDPR. A data sharing agreement is most likely to be needed when personal data is being shared between commercial organizations acting as joint data controllers, because they have to determine and agree on their respective roles and responsibilities, such as the purpose and legal basis of the data sharing, the rights of the data subjects, the security measures, and the liability for any breaches. A data sharing agreement is not mandatory, but it is good practice and can help to avoid disputes and confusion. A data sharing agreement may not be needed or may be less detailed in the other scenarios, depending on the circumstances and the nature of the data. For example, anonymized data is not personal data under the GDPR and does not require a data sharing agreement, although it may still be subject to other contractual or ethical obligations. Personal data that is proactively shared by a controller to support a police investigation may be covered by a legal obligation or a public interest, and the controller may not have much control over how the data is used by the police. Personal data that is shared with a public authority with powers to require the personal data to be disclosed may also be subject to a legal obligation or a public interest, and the controller may have to comply with the authority's request without a data sharing agreement. Reference:
Data sharing agreements | ICO, which provides guidance on the benefits and contents of a data sharing agreement.
Data Sharing Agreement - the Definition - GDPR Summary, which explains what a data sharing agreement is and when it can be used.
The role of data sharing and the GDPR | Data Republic, which discusses the impact of the GDPR on data sharing practices.


NEW QUESTION # 141
As a result of the European Court of Justice's ruling in the case of Google v. Spain, search engines outside the EEA are also likely to be subject to the Regulation's right to be forgotten. This holds true if the activities of an EU subsidiary and its U.S. parent are what?

  • A. Supervised by the same Data Protection Officer.
  • B. Inextricably linked in their businesses.
  • C. Bound by a standard contractual clause.
  • D. Consistent with Privacy Shield requirements

Answer: B

Explanation:
According to the CIPP/E study guide, the Court of Justice of the European Union (CJEU) ruled in the case of Google Spain SL, Google Inc. v Agencia Espanola de Proteccion de Datos (AEPD), Mario Costeja Gonzalez1 that an Internet search engine operator is responsible for the processing of personal data that appear on web pages published by third parties, and that such operator must comply with the EU data protection law when it has an establishment in the EU. The CJEU held that Google Spain and Google Inc. were inextricably linked in their businesses, since Google Spain promoted and sold advertising space offered by Google Inc., which oriented its activity towards the inhabitants of Spain. Therefore, Google Inc. was subject to the EU data protection law through its subsidiary Google Spain, even though the personal data processing was carried out by Google Inc. outside the EU. This implies that search engines outside the EEA are also likely to be subject to the Regulation's right to be forgotten if they have an establishment in the EU that is inextricably linked to their parent company. Reference: 1: CIPP/E study guide, page 16; Google Spain v AEPD and Mario Costeja Gonzalez


NEW QUESTION # 142
SCENARIO
Please use the following to answer the next question:
Joe started the Gummy Bear Company in 2000 from his home in Vermont, USA. Today, it is a multi-billion-dollar candy company operating in every continent. All of the company's IT servers are located in Vermont. This year Joe hires his son Ben to join the company and head up Project Big, which is a major marketing strategy to triple gross revenue in just 5 years. Ben graduated with a PhD in computer software from a top university. Ben decided to join his father's company, but is also secretly working on launching a new global online dating website company called Ben Knows Best.
Ben is aware that the Gummy Bear Company has millions of customers and believes that many of them might also be interested in finding their perfect match. For Project Big, Ben redesigns the company's online web portal and requires customers in the European Union and elsewhere to provide additional personal information in order to remain a customer. Project Ben begins collecting data about customers' philosophical beliefs, political opinions and marital status.
If a customer identifies as single, Ben then copies all of that customer's personal data onto a separate database for Ben Knows Best. Ben believes that he is not doing anything wrong, because he explicitly asks each customer to give their consent by requiring them to check a box before accepting their information. As Project Big is an important project, the company also hires a first year college student named Sam, who is studying computer science to help Ben out.
Ben calls out and Sam comes across the Ben Knows Best database. Sam is planning on going to Ireland over Spring Beak with 10 of his friends, so he copies all of the customer information of people that reside in Ireland so that he and his friends can contact people when they are in Ireland.
Joe also hires his best friend's daughter, Alice, who just graduated from law school in the U.S., to be the company's new General Counsel. Alice has heard about the GDPR, so she does some research on it. Alice approaches Joe and informs him that she has drafted up Binding Corporate Rules for everyone in the company to follow, as it is important for the company to have in place a legal mechanism to transfer data internally from the company's operations in the European Union to the U.S.
Joe believes that Alice is doing a great job, and informs her that she will also be in-charge of handling a major lawsuit that has been brought against the company in federal court in the U.S. To prepare for the lawsuit, Alice instructs the company's IT department to make copies of the computer hard drives from the entire global sales team, including the European Union, and send everything to her so that she can review everyone's information. Alice believes that Joe will be happy that she did the first level review, as it will save the company a lot of money that would otherwise be paid to its outside law firm.
When Ben had the company collect additional data from its customers, the most serious violation of the GDPR occurred because the processing of the data created what?

  • A. A significant risk due to the lack of an informed consent mechanism.
  • B. An information security risk by copying the data into a new database.
  • C. A potential legal liability and financial exposure from its customers.
  • D. A significant risk to the customers' fundamental rights and freedoms.

Answer: D


NEW QUESTION # 143
The Planet 49 CJEU Judgement applies to?

  • A. Cookies used only by third parties.
  • B. Cookies regardless of whether the data accessed is personal or not.
  • C. Cookies that are deemed technically necessary.
  • D. Cookies where the data accessed is considered as personal data only.

Answer: B

Explanation:
Reference https://www.twobirds.com/en/news/articles/2019/global/planet49-cjeu-rules-on-cookie-consent


NEW QUESTION # 144
What term BEST describes the European model for data protection?

  • A. Comprehensive
  • B. Sectoral
  • C. Self-regulatory
  • D. Market-based

Answer: A

Explanation:
The European model for data protection is best described as comprehensive, because it covers all sectors and types of data processing, and applies to any organization that targets or collects data related to people in the EU. The GDPR is the main legal instrument of this model, and it establishes a set of principles, rights, and obligations for data protection, as well as a harmonized framework for enforcement and cooperation among EU member states and data protection authorities. The GDPR also aims to ensure consistency with other EU laws and policies, such as the ePrivacy Directive, the Charter of Fundamental Rights, and the European Data Strategy. The European model for data protection is based on the recognition of data protection as a fundamental right and a public interest, and it reflects the EU's values and objectives of promoting human dignity, democracy, and the rule of law. Reference:
Data protection in the EU, section "Legislation"
What is GDPR, the EU's new data protection law?, section "What is the GDPR?" European Data Protection, Third Edition, page 1, section "Introduction" European Data Protection: Law and Practice, page 1, section "Introduction"


NEW QUESTION # 145
SCENARIO
Please use the following to answer the next question:
Jane Stan's her new role as a Data Protection Officer (DPO) at a Malta-based company that allows anyone to buy and sell cryptocurrencies via its online platform. The company stores and processes the personal data of its customers in a dedicated data center located in Malta (EU).
People wishing to trade cryptocurrencies are required to open an online account on the platform. They then must successfully pass a KYC due diligence procedure aimed at preventing money laundering and ensuring compliance with applicable financial regulations.
The non-European customers are also required to waive all their GDPR rights by reading a disclaimer written in bold and belong a checkbox on a separate page in order to get their account approved on the platform.
The customers must likewise accept the terms of service of the platform. The terms of service also include a privacy policy section, saying, among other things, that if a Are the cybersecurity assessors required to sign a data processing agreement with the company in order to comply with the GDPR''

  • A. Yes. the assessors a-e considered to be joint data controllers and must sign a mutual data processing agreement.
  • B. No. the assessors do not quality as data processors as they do not copy the data to their facilities.
  • C. No, the assessors do not quality as data processors as they only have access to encrypted data.
  • D. Yes, the assessors are data processors and their processing of personal data must be governed by a separate contract or other legal act.

Answer: D

Explanation:
According to the GDPR, a data processor is any person or entity that processes personal data on behalf of a data controller1. A data controller is the one who determines the purposes and means of the processing of personal data1. A data processing agreement (DPA) is a contractual document that sets out the rights and obligations of both parties regarding data protection2. The GDPR requires that a data controller who engages a data processor must enter into a written contract or legal act along the lines set out in Article 28.3 of the GDPR3. The DPA must specify, among other things, the subject matter, duration, nature and purpose of the processing, the type of personal data and categories of data subjects, and the obligations and rights of the controller3.
In this scenario, the company is the data controller, as it determines the purposes and means of processing the personal data of its customers. The cybersecurity assessors are data processors, as they process the personal data of the customers on behalf of the company. The assessors have access to the personal data, even if it is encrypted, and they perform a specific technical service for the company. Therefore, the assessors are required to sign a DPA with the company in order to comply with the GDPR. The DPA will define the scope, nature and purpose of the processing, the security measures to be implemented, the notification procedures in case of a data breach, and the rights and obligations of both parties. Reference: 1: Article 4 of the GDPR2: Data Processing Agreement (Template) - GDPR.eu3: Article 28 of the GDPR.


NEW QUESTION # 146
SCENARIO
Please use the following to answer the next question:
Joe is the new privacy manager for Who-R-U, a Canadian business that provides DNA analysis. The company is headquartered in Montreal, and all of its employees are located there. The company offers its services to Canadians only: Its website is in English and French, it accepts only Canadian currency, and it blocks internet traffic from outside of Canada (although this solution doesn't prevent all non-Canadian traffic). It also declines to process orders that request the DNA report to be sent outside of Canada, and returns orders that show a non-Canadian return address.
Bob, the President of Who-R-U, thinks there is a lot of interest for the product in the EU, and the company is exploring a number of plans to expand its customer base.
The first plan, collegially called We-Track-U, will use an app to collect information about its current Canadian customer base. The expansion will allow its Canadian customers to use the app while traveling abroad. He suggests that the company use this app to gather location information. If the plan shows promise, Bob proposes to use push notifications and text messages to encourage existing customers to pre-register for an EU version of the service. Bob calls this work plan, We-Text-U. Once the company has gathered enough pre- registrations, it will develop EU-specific content and services.
Another plan is called Customer for Life. The idea is to offer additional services through the company's app, like storage and sharing of DNA information with other applications and medical providers. The company's contract says that it can keep customer DNA indefinitely, and use it to offer new services and market them to customers. It also says that customers agree not to withdraw direct marketing consent. Paul, the marketing director, suggests that the company should fully exploit these provisions, and that it can work around customers' attempts to withdraw consent because the contract invalidates them.
The final plan is to develop a brand presence in the EU. The company has already begun this process. It is in the process of purchasing the naming rights for a building in Germany, which would come with a few offices that Who-R-U executives can use while traveling internationally. The office doesn't include any technology or infrastructure; rather, it's simply a room with a desk and some chairs.
On a recent trip concerning the naming-rights deal, Bob's laptop is stolen. The laptop held unencrypted DNA reports on 5,000 Who-R-U customers, all of whom are residents of Canad a. The reports include customer name, birthdate, ethnicity, racial background, names of relatives, gender, and occasionally health information.
The Customer for Life plan may conflict with which GDPR provision?

  • A. Article 6, which requires processing to be lawful.
  • B. Article 7, which requires consent to be as easy to withdraw as it is to give.
  • C. Article 16, which provides data subjects with a rights to rectification.
  • D. Article 20, which gives data subjects a right to data portability.

Answer: B


NEW QUESTION # 147
A well-known video production company, based in Spain but specializing in documentaries filmed worldwide, has just finished recording several hours of footage featuring senior citizens in the streets of Madrid. Under what condition would the company NOT be required to obtain the consent of everyone whose image they use for their documentary?

  • A. If the company limits the footage to data subjects solely of legal age.
  • B. If obtaining consent is deemed voluntary by local legislation.
  • C. If the company's status as a documentary provider allows it to claim legitimate interest.
  • D. If obtaining consent is deemed to involve disproportionate effort.

Answer: B


NEW QUESTION # 148
After leaving the EU under the terms of Brexit, the United Kingdom will seek an adequacy determination. What is the reason for this?

  • A. The UK is now a third country because it's no longer subject to the GDPR.
  • B. The UK is less trustworthy now that its not part of the Union.
  • C. The Insurance Commissioner determined that an adequacy determination is required by the Data Protection Act.
  • D. Adequacy determinations automatically lapse when a Member State leaves the EU.

Answer: A

Explanation:
Reference https://www.euractiv.com/section/digital/news/commission-must-refuse-uk-data-adequacy-rights- group-says/


NEW QUESTION # 149
What must be included in a written agreement between the controller and processor in relation to processing conducted on the controller's behalf?

  • A. An obligation on the processor to assist the controller in complying with the controller's obligations to notify the supervisory authority about personal data breaches.
  • B. An obligation on the processor to report any personal data breach to the controller within 72 hours.
  • C. An obligation on both parties to agree to a termination of the agreement if the other party is responsible for a personal data breach.
  • D. An obligation on both parties to report any serious personal data breach to the supervisory authority.

Answer: D


NEW QUESTION # 150
When assessing the level of risk created by a data breach, which of the following would NOT have to be taken into consideration?

  • A. The size of any data processor involved.
  • B. The ease of identification of individuals.
  • C. The nature, sensitivity and volume of personal data.
  • D. The special characteristics of the data controller.

Answer: A


NEW QUESTION # 151
......

Read Online CIPP-E Test Practice Test Questions Exam Dumps: https://www.testvalid.com/CIPP-E-exam-collection.html

The  CIPP-E PDF Dumps Greatest for the IAPP Exam Study Guide!: https://drive.google.com/open?id=1LjamU6dH_iq4gPHkNyM2C6WnAYi82PYk