CIPP-E Dumps 2022 New IAPP CIPP-E Exam Questions [Q48-Q70]

Share

CIPP-E Dumps 2022 - New IAPP CIPP-E Exam Questions

Free CIPP-E braindumps download (CIPP-E exam dumps Free Updated)


Review the IAPP CIPP/E Certification Exam

There is a study guide for IAPP CIPP/E certification Exam

Learn about the IAPP CIPP / E certification exam

The IAPP defines this certification as perfect for “the go-to person for privacy laws, guidelines and frameworks” in a company. This target market can include many other senior personal privacy or security experts with IT training experience, but can also include individuals belonging to the government, legal, or administrative companies whose job it is to keep the information confidential. and also in terms of security. This is doubled for those involved in legal and compliance requests, information monitoring, information management, and even personal (as privacy is an individual matter at heart, including personal data).

Since privacy protection and private data protection are generally heavily managed and based on legal systems and frameworks, the IAPP provides variations of CIPP accreditation where this material and coverage has been “localized” for directives. applicable laws and regulations. and ideal techniques. There are five such versions available: Asia (CIPP / A), Canada (CIPP / C), Europe (CIPP / E), US government (CIPP / G), and US private sector (CIPP) / USA). At the time of writing, CIPP / E necessarily offers the most direct and specific coverage of GDPR topics.

This exam guide is designed to assist you to evaluate if you prepare to successfully finish the IAPP CIPP/E examination.

 

NEW QUESTION 48
SCENARIO
Please use the following to answer the next question:
Anna and Frank both work at Granchester University. Anna is a lawyer responsible for data protection, while Frank is a lecturer in the engineering department. The University maintains a number of types of records:
Student records, including names, student numbers, home addresses, pre-university information, university attendance and performance records, details of special educational needs and financial information.
Staff records, including autobiographical materials (such as curricula, professional contact files, student evaluations and other relevant teaching files).
Alumni records, including birthplaces, years of birth, dates of matriculation and conferrals of degrees. These records are available to former students after registering through Granchester's Alumni portal. Department for Education records, showing how certain demographic groups (such as first-generation students) could be expected, on average, to progress. These records do not contain names or identification numbers.
Under their security policy, the University encrypts all of its personal data records in transit and at rest.
In order to improve his teaching, Frank wants to investigate how his engineering students perform in relational to Department for Education expectations. He has attended one of Anna's data protection training courses and knows that he should use no more personal data than necessary to accomplish his goal. He creates a program that will only export some student data: previous schools attended, grades originally obtained, grades currently obtained and first time university attended. He wants to keep the records at the individual student level. Mindful of Anna's training, Frank runs the student numbers through an algorithm to transform them into different reference numbers. He uses the same algorithm on each occasion so that he can update each record over time.
One of Anna's tasks is to complete the record of processing activities, as required by the GDPR. After receiving her email reminder, as required by the GDPR. After receiving her email reminder, Frank informs Anna about his performance database.
Ann explains to Frank that, as well as minimizing personal data, the University has to check that this new use of existing data is permissible. She also suspects that, under the GDPR, a risk analysis may have to be carried out before the data processing can take place. Anna arranges to discuss this further with Frank after she has done some additional research.
Frank wants to be able to work on his analysis in his spare time, so he transfers it to his home laptop (which is not encrypted). Unfortunately, when Frank takes the laptop into the University he loses it on the train. Frank has to see Anna that day to discuss compatible processing. He knows that he needs to report security incidents, so he decides to tell Anna about his lost laptop at the same time.
Which of the University's records does Anna NOT have to include in her record of processing activities?

  • A. Department for Education records
  • B. Frank's performance database
  • C. Staff and alumni records
  • D. Student records

Answer: B

 

NEW QUESTION 49
Which of the following describes a mandatory requirement for a group of undertakings that wants to appoint a single data protection officer?

  • A. The data protection officer must be easily accessible from each establishment where the undertakings are located.
  • B. The group of undertakings must be comprised of organizations of similar sizes and functions.
  • C. The group of undertakings must obtain approval from a supervisory authority.
  • D. The data protection officer must be located in the country where the data controller has its main establishment.

Answer: A

 

NEW QUESTION 50
Which of the following describes a mandatory requirement for a group of undertakings that wants to appoint a single data protection officer?

  • A. The data protection officer must be easily accessible from each establishment where the undertakings are located.
  • B. The group of undertakings must be comprised of organizations of similar sizes and functions.
  • C. The group of undertakings must obtain approval from a supervisory authority.
  • D. The data protection officer must be located in the country where the data controller has its main establishment.

Answer: A

Explanation:
Explanation/Reference: https://www.privacy-regulation.eu/en/article-37-designation-of-the-data-protection-officer- GDPR.htm

 

NEW QUESTION 51
An unforeseen power outage results in company Z's lack of access to customer data for six hours. According to article 32 of the GDPR, this is considered a breach. Based on the WP 29's February, 2018 guidance, company Z should do which of the following?

  • A. Document the loss of availability to demonstrate accountability
  • B. Notify affected individuals that their data was unavailable for a period of time.
  • C. Notify the supervisory authority about the loss of availability
  • D. Conduct a thorough audit of all security systems

Answer: C

Explanation:
Explanation/Reference: https://www.google.com/url?
sa=t&rct=j&q=&esrc=s&source=web&cd=&ved=2ahUKEwihmsidxtTqAhXvQUEAHXRaAdYQFjABegQIARAB& url=https%3A%2F%2Fec.europa.eu%2Fnewsroom%2Farticle29%2Fdocument.cfm%3Fdoc_id%
3D49827&usg=AOvVaw2uhYsKyRzJ6lwhQyiMURJF (5)

 

NEW QUESTION 52
A grade school is planning to use facial recognition to track student attendance. Which of the following may provide a lawful basis for this processing?

  • A. Processing is necessary for the legitimate interests pursed by the school.
  • B. The school places a notice near each camera.
  • C. The school gets explicit consent from the students.
  • D. A state law requires facial recognition to verify attendance.

Answer: B

 

NEW QUESTION 53
When assessing the level of risk created by a data breach, which of the following would NOT have to be taken into consideration?

  • A. The special characteristics of the data controller.
  • B. The ease of identification of individuals.
  • C. The nature, sensitivity and volume of personal data.
  • D. The size of any data processor involved.

Answer: D

 

NEW QUESTION 54
SCENARIO
Please use the following to answer the next question:
BHealthy, a company based in Italy, is ready to launch a new line of natural products, with a focus on sunscreen. The last step prior to product launch is for BHealthy to conduct research to decide how extensively to market its new line of sunscreens across Europe. To do so, BHealthy teamed up with Natural Insight, a company specializing in determining pricing for natural products. BHealthy decided to share its existing customer information - name, location, and prior purchase history - with Natural Insight. Natural Insight intends to use this information to train its algorithm to help determine the price point at which BHealthy can sell its new sunscreens.
Prior to sharing its customer list, BHealthy conducted a review of Natural Insight's security practices and concluded that the company has sufficient security measures to protect the contact information. Additionally, BHealthy's data processing contractual terms with Natural Insight require continued implementation of technical and organization measures. Also indicated in the contract are restrictions on use of the data provided by BHealthy for any purpose beyond provision of the services, which include use of the data for continued improvement of Natural Insight's machine learning algorithms.
What is the nature of BHealthy and Natural Insight's relationship?

  • A. Natural Insight is the controller because it determines the security measures to implement to protect data it processes; BHealthy is a co-controller because it engaged Natural Insight to determine pricing for the new sunscreens.
  • B. Natural Insight is BHealthy's processor because the companies entered into data processing terms.
  • C. Natural Insight is a controller because it is separately determine the purpose of processing when it uses BHealthy's customer information to improve its machine learning algorithms.
  • D. Natural Insight is BHealthy's processor because BHealthy is sharing its customer information with Natural Insight.

Answer: B

 

NEW QUESTION 55
SCENARIO
Please use the following to answer the next question:
Louis, a long-time customer of Bedrock Insurance, was involved in a minor car accident a few months ago.
Although no one was hurt, Louis has been plagued by texts and calls from a company called Accidentable offering to help him recover compensation for personal injury. Louis has heard about insurance companies selling customers' data to third parties, and he's convinced that Accidentable must have gotten his information from Bedrock Insurance.
Louis has also been receiving an increased amount of marketing information from Bedrock, trying to sell him their full range of their insurance policies.
Perturbed by this, Louis has started looking at price comparison sites on the internet and has been shocked to find that other insurers offer much cheaper rates than Bedrock, even though he has been a loyal customer for many years. When his Bedrock policy comes up for renewal, he decides to switch to Zantrum Insurance.
In order to activate his new insurance policy, Louis needs to supply Zantrum with information about his No Claims bonus, his vehicle and his driving history. After researching his rights under the GDPR, he writes to ask Bedrock to transfer his information directly to Zantrum. He also takes this opportunity to ask Bedrock to stop using his personal data for marketing purposes.
Bedrock supplies Louis with a PDF and XML (Extensible Markup Language) versions of his No Claims Certificate, but tells Louis it cannot transfer his data directly to Zantrum as this is not technically feasible.
Bedrock also explains that Louis's contract included a provision whereby Louis agreed that his data could be used for marketing purposes; according to Bedrock, it is too late for Louis to change his mind about this. It angers Louis when he recalls the wording of the contract, which was filled with legal jargon and very confusing.
In the meantime, Louis is still receiving unwanted calls from Accidentable Insurance. He writes to Accidentable to ask for the name of the organization that supplied his details to them. He warns Accidentable that he plans to complain to the data protection authority, because he thinks their company has been using his data unlawfully. His letter states that he does not want his data being used by them in any way.
Accidentable's response letter confirms Louis's suspicions. Accidentable is Bedrock Insurance's wholly owned subsidiary, and they received information about Louis's accident from Bedrock shortly after Louis submitted his accident claim. Accidentable assures Louis that there has been no breach of the GDPR, as Louis's contract included, a provision in which he agreed to share his information with Bedrock's affiliates for business purposes.
Louis is disgusted by the way in which he has been treated by Bedrock, and writes to them insisting that all his information be erased from their computer system.
After Louis has exercised his right to restrict the use of his data, under what conditions would Accidentable have grounds for refusing to comply?

  • A. If Accidentable is entitled to use of the data as an affiliate of Bedrock.
  • B. If the data becomes necessary to defend Accidentable's legal rights.
  • C. If Accidentable also uses the data to conduct public health research.
  • D. If the accuracy of the data is not an aspect that Louis is disputing.

Answer: A

Explanation:
Explanation/Reference:

 

NEW QUESTION 56
A Spanish electricity customer calls her local supplier with questions about the company's upcoming merger. Specifically, the customer wants to know the recipients to whom her personal data will be disclosed once the merger is final. According to Article 13 of the GDPR, what must the company do before providing the customer with the requested information?

  • A. Verify that the personal data has not already been sent to the customer.
  • B. Verify that the identity of the customer can be proven by other means.
  • C. Verify that the purpose of the request from the customer is in line with the GDPR.
  • D. Verify that the request is applicable to the data collected before the GDPR entered into force.

Answer: D

 

NEW QUESTION 57
Which of the following is one of the supervisory authority's investigative powers?

  • A. To notify the controller or the processor of an alleged infringement of the GDPR.
  • B. To determine whether a controller or processor has the right to a judicial remedy concerning a compensation decision made against them.
  • C. To require data controllers to provide them with written notification of all new processing activities.
  • D. To require that controllers or processors adopt approved data protection certification mechanisms.

Answer: A

 

NEW QUESTION 58
Under Article 21 of the GDPR, a controller must stop profiling when requested by a data subject, unless it can demonstrate compelling legitimate grounds that override the interests of the individual. In the Guidelines on Automated individual decision-making and Profiling, the WP 29 says the controller needs to do all of the following to demonstrate that it has such legitimate grounds EXCEPT?

  • A. Carry out an exercise that weighs the interests of the controller and the basis for the data subject's objection.
  • B. Demonstrate that the profiling is for the purposes of direct marketing.
  • C. Consider the impact of the profiling on the data subject's interest, rights and freedoms.
  • D. Consider the importance of the profiling to their particular objective.

Answer: B

Explanation:
Explanation/Reference: https://gdpr-info.eu/art-21-gdpr/

 

NEW QUESTION 59
What permissions are required for a marketer to send an email marketing message to a consumer in the EU?

  • A. A notice that the consumer's email address will be used for marketing purposes.
  • B. No prior permission required, but an opt-out requirement on all emails sent to consumers.
  • C. A pre-checked box stating that the consumer agrees to receive email marketing.
  • D. A prior opt-in consent for consumers unless they are already customers.

Answer: D

 

NEW QUESTION 60
What is the most frequently used mechanism for legitimizing cross-border data transfer?

  • A. Approved Code of Conduct.
  • B. Standard Contractual Clauses.
  • C. Derogations.
  • D. Binding Corporate Rules.

Answer: B

 

NEW QUESTION 61
SCENARIO
Please use the following to answer the next Question:
Louis, a long-time customer of Bedrock Insurance, was involved in a minor car accident a few months ago. Although no one was hurt, Louis has been plagued by texts and calls from a company called Accidentable offering to help him recover compensation for personal injury. Louis has heard about insurance companies selling customers' data to third parties, and he's convinced that Accidentable must have gotten his information from Bedrock Insurance.
Louis has also been receiving an increased amount of marketing information from Bedrock, trying to sell him their full range of their insurance policies.
Perturbed by this, Louis has started looking at price comparison sites on the internet and has been shocked to find that other insurers offer much cheaper rates than Bedrock, even though he has been a loyal customer for many years. When his Bedrock policy comes up for renewal, he decides to switch to Zantrum Insurance.
In order to activate his new insurance policy, Louis needs to supply Zantrum with information about his No Claims bonus, his vehicle and his driving history. After researching his rights under the GDPR, he writes to ask Bedrock to transfer his information directly to Zantrum. He also takes this opportunity to ask Bedrock to stop using his personal data for marketing purposes.
Bedrock supplies Louis with a PDF and XML (Extensible Markup Language) versions of his No Claims Certificate, but tells Louis it cannot transfer his data directly to Zantrum as this is not technically feasible. Bedrock also explains that Louis's contract included a provision whereby Louis agreed that his data could be used for marketing purposes; according to Bedrock, it is too late for Louis to change his mind about this. It angers Louis when he recalls the wording of the contract, which was filled with legal jargon and very confusing.
In the meantime, Louis is still receiving unwanted calls from Accidentable Insurance. He writes to Accidentable to ask for the name of the organization that supplied his details to them. He warns Accidentable that he plans to complain to the data protection authority, because he thinks their company has been using his data unlawfully. His letter states that he does not want his data being used by them in any way.
Accidentable's response letter confirms Louis's suspicions. Accidentable is Bedrock Insurance's wholly owned subsidiary, and they received information about Louis's accident from Bedrock shortly after Louis submitted his accident claim. Accidentable assures Louis that there has been no breach of the GDPR, as Louis's contract included, a provision in which he agreed to share his information with Bedrock's affiliates for business purposes.
Louis is disgusted by the way in which he has been treated by Bedrock, and writes to them insisting that all his information be erased from their computer system.
Based on the GDPR's position on the use of personal data for direct marketing purposes, which of the following is true about Louis's rights as a data subject?

  • A. Louis does not have the right to object to the use of his data if Bedrock can demonstrate compelling legitimate grounds for the processing.
  • B. Louis has the right to object to the use of his data, unless his data is required by Bedrock for the purpose of exercising a legal claim.
  • C. Louis does not have the right to object to the use of his data because he previously consented to it.
  • D. Louis has the right to object at any time to the use of his data and Bedrock must honor his request to cease use.

Answer: D

 

NEW QUESTION 62
SCENARIO
Please use the following to answer the next question:
Due to rapidly expanding workforce, Company A has decided to outsource its payroll function to Company B.
Company B is an established payroll service provider with a sizable client base and a solid reputation in the industry.
Company B's payroll solution for Company A relies on the collection of time and attendance data obtained via a biometric entry system installed in each of Company A's factories. Company B won't hold any biometric data itself, but the related data will be uploaded to Company B's UK servers and used to provide the payroll service. Company B's live systems will contain the following information for each of Company A's employees:
* Name
* Address
* Date of Birth
* Payroll number
* National Insurance number
* Sick pay entitlement
* Maternity/paternity pay entitlement
* Holiday entitlement
* Pension and benefits contributions
* Trade union contributions
Jenny is the compliance officer at Company A.
She first considers whether Company A needs to carry out a data protection impact assessment in relation to the new time and attendance system, but isn't sure whether or not this is required.
Jenny does know, however, that under the GDPR there must be a formal written agreement requiring Company B to use the time and attendance data only for the purpose of providing the payroll service, and to apply appropriate technical and organizational security measures for safeguarding the data. Jenny suggests that Company B obtain advice from its data protection officer. The company doesn't have a DPO but agrees, in the interest of finalizing the contract, to sign up for the provisions in full. Company A enters into the contract.
Weeks later, while still under contract with Company A, Company B embarks upon a separate project meant to enhance the functionality of its payroll service, and engages Company C to help. Company C agrees to extract all personal data from Company B's live systems in order to create a new database for Company B.
This database will be stored in a test environment hosted on Company C's U.S. server. The two companies agree not to include any data processing provisions in their services agreement, as data is only being used for IT testing purposes.
Unfortunately, Company C's U.S. server is only protected by an outdated IT security system, and suffers a cyber security incident soon after Company C begins work on the project. As a result, data relating to Company A's employees is visible to anyone visiting Company C's website. Company A is unaware of this until Jenny receives a letter from the supervisory authority in connection with the investigation that ensues. As soon as Jenny is made aware of the breach, she notifies all affected employees.
Under the GDPR, which of Company B's actions would NOT be likely to trigger a potential enforcement action?

  • A. Their engagement of Company C to improve their payroll service.
  • B. Their omission of data protection provisions in their contract with Company C.
  • C. Their decision to operate without a data protection officer.
  • D. Their failure to provide sufficient security safeguards to Company A's data.

Answer: A

 

NEW QUESTION 63
SCENARIO
Please use the following to answer the next question:
Anna and Frank both work at Granchester University. Anna is a lawyer responsible for data protection, while Frank is a lecturer in the engineering department. The University maintains a number of types of records:
* Student records, including names, student numbers, home addresses, pre-university information, university attendance and performance records, details of special educational needs and financial information.
* Staff records, including autobiographical materials (such as curricula, professional contact files, student evaluations and other relevant teaching files).
* Alumni records, including birthplaces, years of birth, dates of matriculation and conferrals of degrees.
These records are available to former students after registering through Granchester's Alumni portal.
* Department for Education records, showing how certain demographic groups (such as first-generation students) could be expected, on average, to progress. These records do not contain names or identification numbers.
* Under their security policy, the University encrypts all of its personal data records in transit and at rest.
In order to improve his teaching, Frank wants to investigate how his engineering students perform in relational to Department for Education expectations. He has attended one of Anna's data protection training courses and knows that he should use no more personal data than necessary to accomplish his goal. He creates a program that will only export some student data: previous schools attended, grades originally obtained, grades currently obtained and first time university attended. He wants to keep the records at the individual student level. Mindful of Anna's training, Frank runs the student numbers through an algorithm to transform them into different reference numbers. He uses the same algorithm on each occasion so that he can update each record over time.
One of Anna's tasks is to complete the record of processing activities, as required by the GDPR. After receiving her email reminder, as required by the GDPR. After receiving her email reminder, Frank informs Anna about his performance database.
Ann explains to Frank that, as well as minimizing personal data, the University has to check that this new use of existing data is permissible. She also suspects that, under the GDPR, a risk analysis may have to be carried out before the data processing can take place. Anna arranges to discuss this further with Frank after she has done some additional research.
Frank wants to be able to work on his analysis in his spare time, so he transfers it to his home laptop (which is not encrypted). Unfortunately, when Frank takes the laptop into the University he loses it on the train. Frank has to see Anna that day to discuss compatible processing. He knows that he needs to report security incidents, so he decides to tell Anna about his lost laptop at the same time.
Anna will find that a risk analysis is NOT necessary in this situation as long as?

  • A. The algorithms that Frank uses for the processing are technologically sound
  • B. The data subjects gave their unambiguous consent for the original processing
  • C. The data subjects are no longer current students of Frank's
  • D. The processing will not negatively affect the rights of the data subjects

Answer: B

 

NEW QUESTION 64
What is the consequence if a processor makes an independent decision regarding the purposes and means of processing it carries out on behalf of a controller?

  • A. The controller will be required to demonstrate that the unauthorized processing negatively affected one or more of the parties involved
  • B. The processor will be considered to be a controller in respect of the processing concerned
  • C. The controller will be liable to pay an administrative fine
  • D. The processor will be liable to pay compensation to affected data subjects

Answer: D

Explanation:
Explanation/Reference: https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection- regulation-gdpr/key-definitions/controllers-and-processors/

 

NEW QUESTION 65
When does the GDPR provide more latitude for a company to process data beyond its original collection purpose?

  • A. When the data serves legitimate interest of third parties.
  • B. When the data has been pseudonymized.
  • C. When the data subject has failed to use a provided opt-out mechanism.
    Section: (none)
    Explanation
  • D. When the data is protected by technological safeguards.

Answer: A

 

NEW QUESTION 66
SCENARIO
Please use the following to answer the next question:
T-Craze, a German-headquartered specialty t-shirt company, was successfully selling to large German metropolitan cities. However, after a recent merger with another German-based company that was selling to a broader European market, T-Craze revamped its marketing efforts to sell to a wider audience. These efforts included a complete redesign of its logo to reflect the recent merger, and improvements to its website meant to capture more information about visitors through the use of cookies.
T-Craze also opened various office locations throughout Europe to help expand its business. While Germany continued to host T-Craze's headquarters and main product-design office, its French affiliate became responsible for all marketing and sales activities. The French affiliate recently procured the services of Right Target, a renowned marketing firm based in the Philippines, to run its latest marketing campaign. After thorough research, Right Target determined that T-Craze is most successful with customers between the ages of 18 and 22. Thus, its first campaign targeted university students in several European capitals, which yielded nearly 40% new customers for T-Craze in one quarter. Right Target also ran subsequent campaigns for T- Craze, though with much less success.
The last two campaigns included a wider demographic group and resulted in countless unsubscribe requests, including a large number in Spain. In fact, the Spanish data protection authority received a complaint from Sofia, a mid-career investment banker. Sofia was upset after receiving a marketing communication even after unsubscribing from such communications from the Right Target on behalf of T-Craze.
Which of the following is T-Craze's lead supervisory authority?

  • A. Germany, because that is where T-Craze is headquartered.
  • B. T-Craze may choose its lead supervisory authority where any of its affiliates are based, because it has presence in several European countries.
  • C. Spain, because that is T-Craze's primary market based on its marketing campaigns.
  • D. France, because that is where T-Craze conducts processing of personal information.

Answer: C

 

NEW QUESTION 67
Read the following steps:
* Discover which employees are accessing cloud services and from which devices and apps Lock down the data in those apps and devices
* Monitor and analyze the apps and devices for compliance
* Manage application life cycles
* Monitor data sharing
An organization should perform these steps to do which of the following?

  • A. Institute a GDPR-compliant employee monitoring process.
  • B. Ensure cloud vendors are complying with internal data use policies.
  • C. Maintain a secure Bring Your Own Device (BYOD) program.
  • D. Pursue a GDPR-compliant Privacy by Design process.

Answer: C

 

NEW QUESTION 68
Under which of the following conditions does the General Data Protection Regulation NOT apply to the processing of personal data?

  • A. When the personal data is processed by an individual only for their household activities
  • B. When the personal data is processed only in non-electronic form
  • C. When the personal data is collected and then pseudonymised by the controller
  • D. When the personal data is held by the controller but not processed for further purposes

Answer: C

Explanation:
Explanation/Reference: https://gdpr-info.eu/art-6-gdpr/

 

NEW QUESTION 69
SCENARIO
Please use the following to answer the next question:
Outliers Inc. is a travel service company which has lost substantial revenue over the last few years. Their new manager, Jonathan, suspects that this is partly due to the company's outdated website. After doing some research, he meets with a sales representative from the up-and-coming IT company ZenFiTech, hoping that they can design a new, cutting-edge website for Outliers Inc.'s foundering business.
During negotiations, a ZenFiTech representative describes a plan for gathering more customer information through detailed questionnaires, which could be used to tailor their preferences to specific travel destinations. Outliers Inc. can choose any number of data categories - age, income, ethnicity - that would help them best accomplish their goals. Jonathan loves this idea, but would also like to have some way of gauging how successful this approach is, especially since the questionnaires will require customers to provide explicit consent to having their data collected. The ZenFiTech representative suggests that they also run a program to analyze the new website's traffic, in order to get a better understanding of how customers are using it. He explains his plan to place a number of cookies on customer devices. The cookies will allow the company to collect IP addresses and other information, such as the sites from which the customers came, how much time they spend on the Outliers Inc. website, and which pages on the site they visit. All of this information will be compiled in log files, which ZenFiTech will analyze by means of a special program. Outliers Inc. would receive aggregate statistics to help them evaluate the website's effectiveness. Jonathan enthusiastically engages ZenFiTech for these services.
With regard to Outliers Inc.'s use of website cookies, which of the following statements is correct?

  • A. Because not all of the cookies are strictly necessary to enable the use of a service requested from Outliers Inc., consent requirements apply to their use of cookies.
  • B. Because of the categories of data involved, explicit consent for the use of cookies must be obtained separately from customers.
  • C. Because ZenFiTech will receive only aggregate statistics of data collected from the cookies, no additional consent is necessary.
  • D. Because the use of cookies involves the potential for location tracking, explicit consent must be obtained from customers.

Answer: B

 

NEW QUESTION 70
......

Verified CIPP-E dumps Q&As - Pass Guarantee Exam Dumps Test Engine: https://www.testvalid.com/CIPP-E-exam-collection.html

CIPP-E Dumps for Pass Guaranteed - Pass CIPP-E Exam: https://drive.google.com/open?id=1LjamU6dH_iq4gPHkNyM2C6WnAYi82PYk