
Pass CIPP-E Exam - Real Test Engine PDF with 252 Questions
Get New CIPP-E Certification Practice Test Questions Exam Dumps
Target Audience
The complete form of the CIPP-E is the Certified Information Privacy Professional/Europe. The exam, in particular, is designed for data protection officers who are responsible for keeping tabs on compliance, being in charge of internal data security, training staff for data processing, and auditing. However, such a test is more specific on trans-border data protection officials.
NEW QUESTION 78
Company X has entrusted the processing of their payroll data to Provider Y.
Provider Y stores this encrypted data on its server. The IT department of Provider Y finds out that someone managed to hack into the system and take a copy of the data from its server. In this scenario, whom does Provider Y have the obligation to notify?
- A. The supervisory authority
- B. The public
- C. Company X
- D. Law enforcement
Answer: D
NEW QUESTION 79
SCENARIO
Please use the following to answer the next question:
Zandelay Fashion ('Zandelay') is a successful international online clothing retailer that employs approximately 650 people at its headquarters based in Dublin, Ireland. Martin is their recently appointed data protection officer, who oversees the company's compliance with the General Data Protection Regulation (GDPR) and other privacy legislation.
The company offers both male and female clothing lines across all age demographics, including children. In doing so, the company processes large amounts of information about such customers, including preferences and sensitive financial information such as credit card and bank account numbers.
In an aggressive bid to build revenue growth, Jerry, the CEO, tells Martin that the company is launching a new mobile app and loyalty scheme that puts significant emphasis on profiling the company's customers by analyzing their purchases. Martin tells the CEO that: (a) the potential risks of such activities means that Zandelay needs to carry out a data protection impact assessment to assess this new venture and its privacy implications; and (b) where the results of this assessment indicate a high risk in the absence of appropriate protection measures. Zandelay may have to undertake a prior consultation with the Irish Data Protection Commissioner before implementing the app and loyalty scheme.
Jerry tells Martin that he is not happy about the prospect of having to directly engage with a supervisory authority and having to disclose details of Zandelay's business plan and associated processing activities.
What must Zandelay provide to the supervisory authority during the prior consultation?
- A. Records showing that customers have explicitly consented to the intended profiling activities.
- B. Certificates that prove Martin's professional qualities and expert knowledge of data protection law.
- C. An evaluation of the complexity of the intended processing.
- D. An of the purposes and means of the intended processing.
Answer: D
NEW QUESTION 80
The GDPR specifies fines that may be levied against data controllers for certain infringements. Which of the following infringements would be subject to the less severe administrative fine of up to 10 million euros (or in the case of an undertaking, up to 2% of the total worldwide annual turnover of the preceding financial year)?
- A. Failure to implement technical and organizational measures to ensure data protection is enshrined by design and default.
- B. Failure to demonstrate that consent was given by the data subject to the processing of their personal data where it is used as the basis for processing.
- C. Failure to process personal information in a manner compatible with its original purpose.
- D. Failure to provide the means for a data subject to rectify inaccuracies in personal data.
Answer: D
NEW QUESTION 81
If a French controller has a car-sharing app available only in Morocco, Algeria and Tunisia, but the data processing activities are carried out by the appointed processor in Spain, the GDPR will apply to the processing of the personal data so long as?
- A. The data processing activities are in Spain.
- B. The individuals are European citizens or residents.
- C. The EU individuals are targeted.
- D. The data controller is in France.
Answer: C
NEW QUESTION 82
Read the following steps:
* Discover which employees are accessing cloud services and from which devices and apps Lock down the data in those apps and devices
* Monitor and analyze the apps and devices for compliance
* Manage application life cycles
* Monitor data sharing
An organization should perform these steps to do which of the following?
- A. Ensure cloud vendors are complying with internal data use policies.
- B. Maintain a secure Bring Your Own Device (BYOD) program.
- C. Pursue a GDPR-compliant Privacy by Design process.
- D. Institute a GDPR-compliant employee monitoring process.
Answer: B
NEW QUESTION 83
An employee of company ABCD has just noticed a memory stick containing records of client data, including their names, addresses and full contact details has disappeared. The data on the stick is unencrypted and in clear text. It is uncertain what has happened to the stick at this stage, but it likely was lost during the travel of an employee. What should the company do?
- A. Invoke the "disproportionate effort" exception under Article 33 to postpone notifying data subjects until more information can be gathered.
- B. Immediately notify all the customers of the company that their information has been accessed by an unauthorized person.
- C. Launch an investigation and if nothing is found within one month, notify the data protection supervisory authority.
- D. Notify as soon as possible the data protection supervisory authority that a data breach may have taken place.
Answer: D
NEW QUESTION 84
In the event of a data breach, which type of information are data controllers NOT required to provide to either the supervisory authorities or the data subjects?
- A. The measures being taken to address the breach.
- B. The predicted consequences of the breach.
- C. The contact details of the appropriate data protection officer.
- D. The type of security safeguards used to protect the data.
Answer: B
Explanation:
Reference https://www.dataprotection.ie/en/organisations/know-your-obligations/data-protection-impact- assessments
NEW QUESTION 85
With the issue of consent, the GDPR allows member states some choice regarding what?
- A. The circumstances in which silence or inactivity may constitute consent
- B. The mechanisms through which consent may be communicated
- C. The timeframe in which data subjects are allowed to withdraw their consent
- D. The age at which children must be required to obtain parental consent
Answer: D
Explanation:
Reference https://gdpr-info.eu/issues/consent/
NEW QUESTION 86
In relation to third countries and international organizations, which of the following shall, along with the supervisory authorities, take appropriate steps to develop international cooperation mechanisms for the enforcement of data protection legislation?
- A. The European Commission
- B. The Council of the European Union.
- C. The European Parliament
- D. The designated Data Protection Officers
Answer: D
NEW QUESTION 87
Please use the following to answer the next question:
WonderkKids provides an online booking service for childcare. Wonderkids is based in France, but hosts its website through a company in Switzerland. As part of their service, WonderKids will pass all personal data provided to them to the childcare provider booked through their system. The type of personal data collected on the website includes the name of the person booking the childcare, address and contact details, as well as information about the children to be cared for including name, age, gender and health information. The privacy statement on Wonderkids' website states the following:
"WonderkKids provides the information you disclose to us through this website to your childcare provider for scheduling and health and safety reasons. We may also use your and your child's personal information for our own legitimate business purposes and we employ a third-party website hosting company located in Switzerland to store the dat a. Any data stored on equipment located in Switzerland meets the European Commission provisions for guaranteeing adequate safeguards for you and your child's personal information. We will only share you and your child's personal information with businesses that we see as adding real value to you. By providing us with any personal data, you consent to its transfer to affiliated businesses and to send you promotional offers."
"We may retain you and your child's personal information for no more than 28 days, at which point the data will be depersonalized, unless your personal information is being used for a legitimate business purpose beyond 28 days where it may be retained for up to 2 years."
"We are processing you and your child's personal information with your consent. If you choose not to provide certain information to us, you may not be able to use our services. You have the right to: request access to you and your child's personal information; rectify or erase you or your child's personal information; the right to correction or erasure of you and/or your child's personal information; object to any processing of you and your child's personal information. You also have the right to complain to the supervisory authority about our data processing activities." What direct marketing information can WonderKids send by email without prior consent of the person booking the childcare?
- A. Marketing information for products or services similar to those purchased from WonderKids.
- B. Marketing information related to other business operations of WonderKids.
- C. No marketing information at all.
- D. Any marketing information at all.
Answer: B
NEW QUESTION 88
Tanya is the Data Protection Officer for Curtains Inc., a GDPR data controller. She has recommended that the company encrypt all personal data at rest. Which GDPR principle is she following?
- A. Accuracy
- B. Storage Limitation
- C. Lawfulness, fairness and transparency
- D. Integrity and confidentiality
Answer: D
NEW QUESTION 89
Which of the following Convention 108+ principles, as amended in 2018, is NOT consistent with a principle found in the GDPR?
- A. The requirement to demonstrate compliance to a supervisory authority.
- B. The necessity of the bulk collection of personal data by the government.
- C. The obligation of companies to declare data breaches.
Answer: A
Explanation:
Reference https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX:52018PC0449&from=HU
NEW QUESTION 90
SCENARIO
Please use the following to answer the next question:
Due to rapidly expanding workforce, Company A has decided to outsource its payroll function to Company B.
Company B is an established payroll service provider with a sizable client base and a solid reputation in the industry.
Company B's payroll solution for Company A relies on the collection of time and attendance data obtained via a biometric entry system installed in each of Company A's factories. Company B won't hold any biometric data itself, but the related data will be uploaded to Company B's UK servers and used to provide the payroll service. Company B's live systems will contain the following information for each of Company A's employees:
* Name
* Address
* Date of Birth
* Payroll number
* National Insurance number
* Sick pay entitlement
* Maternity/paternity pay entitlement
* Holiday entitlement
* Pension and benefits contributions
* Trade union contributions
Jenny is the compliance officer at Company A.
She first considers whether Company A needs to carry out a data protection impact assessment in relation to the new time and attendance system, but isn't sure whether or not this is required.
Jenny does know, however, that under the GDPR there must be a formal written agreement requiring Company B to use the time and attendance data only for the purpose of providing the payroll service, and to apply appropriate technical and organizational security measures for safeguarding the data. Jenny suggests that Company B obtain advice from its data protection officer. The company doesn't have a DPO but agrees, in the interest of finalizing the contract, to sign up for the provisions in full. Company A enters into the contract.
Weeks later, while still under contract with Company A, Company B embarks upon a separate project meant to enhance the functionality of its payroll service, and engages Company C to help. Company C agrees to extract all personal data from Company B's live systems in order to create a new database for Company B.
This database will be stored in a test environment hosted on Company C's U.S. server. The two companies agree not to include any data processing provisions in their services agreement, as data is only being used for IT testing purposes.
Unfortunately, Company C's U.S. server is only protected by an outdated IT security system, and suffers a cyber security incident soon after Company C begins work on the project. As a result, data relating to Company A's employees is visible to anyone visiting Company C's website. Company A is unaware of this until Jenny receives a letter from the supervisory authority in connection with the investigation that ensues. As soon as Jenny is made aware of the breach, she notifies all affected employees.
Under the GDPR, which of Company B's actions would NOT be likely to trigger a potential enforcement action?
- A. Their failure to provide sufficient security safeguards to Company A's data.
- B. Their decision to operate without a data protection officer.
- C. Their engagement of Company C to improve their payroll service.
- D. Their omission of data protection provisions in their contract with Company C.
Answer: C
NEW QUESTION 91
You are the new Data Protection Officer for your company and have to determine whether the company has implemented appropriate technical and organizational measures as required by Article 32 of the GDPR. Which of the following would be the most important to consider when trying to determine this?
- A. How security measures might evolve in the future
- B. Which security measures are endorsed by a majority of experts.
- C. How the public perceives what constitutes adequate security measures
- D. Which kinds of security measures your company has employed in the past
Answer: C
NEW QUESTION 92
The GDPR forbids the practice of "forum shopping", which occurs when companies do what?
- A. Select third-party processors on the basis of cost rather than quality of privacy protection.
- B. File appeals of infringement judgments with more than one EU institution simultaneously.
- C. Designate their main establishment in member state with the most flexible practices.
- D. Choose the data protection officer that is most sympathetic to their business concerns.
Answer: C
NEW QUESTION 93
SCENARIO
Please use the following to answer the next question:
TripBliss Inc. is a travel service company which has lost substantial revenue over the last few years. Their new manager, Oliver, suspects that this is partly due to the company's outdated website. After doing some research, he meets with a sales representative from the up-and-coming IT company Techiva, hoping that they can design a new, cutting-edge website for TripBliss Inc.'s foundering business.
During negotiations, a Techiva representative describes a plan for gathering more customer information through detailed questionnaires, which could be used to tailor their preferences to specific travel destinations.
TripBliss Inc. can choose any number of data categories - age, income, ethnicity - that would help them best accomplish their goals. Oliver loves this idea, but would also like to have some way of gauging how successful this approach is, especially since the questionnaires will require customers to provide explicit consent to having their data collected. The Techiva representative suggests that they also run a program to analyze the new website's traffic, in order to get a better understanding of how customers are using it. He explains his plan to place a number of cookies on customer devices. The cookies will allow the company to collect IP addresses and other information, such as the sites from which the customers came, how much time they spend on the TripBliss Inc. website, and which pages on the site they visit. All of this information will be compiled in log files, which Techiva will analyze by means of a special program. TripBliss Inc. would receive aggregate statistics to help them evaluate the website's effectiveness. Oliver enthusiastically engages Techiva for these services.
Techiva assigns the analytics portion of the project to longtime account manager Leon Santos. As is standard practice, Leon is given administrator rights to TripBliss Inc.'s website, and can authorize access to the log files gathered from it. Unfortunately for TripBliss Inc., however, Leon is taking on this new project at a time when his dissatisfaction with Techiva is at a high point. In order to take revenge for what he feels has been unfair treatment at the hands of the company, Leon asks his friend Fred, a hobby hacker, for help. Together they come up with the following plan: Fred will hack into Techiva's system and copy their log files onto a USB stick.
Despite his initial intention to send the USB to the press and to the data protection authority in order to denounce Techiva, Leon experiences a crisis of conscience and ends up reconsidering his plan. He decides instead to securely wipe all the data from the USB stick and inform his manager that the company's system of access control must be reconsidered.
If TripBliss Inc. decides not to report the incident to the supervisory authority, what would be their BEST defense?
- A. The sensitivity of the categories of data involved in the incident was not substantial enough.
- B. The destruction of the stolen data makes any risk to the affected data subjects unlikely.
- C. The resulting obligation to notify data subjects would involve disproportionate effort.
- D. The incident resulted from the actions of a third-party that were beyond their control.
Answer: D
NEW QUESTION 94
SCENARIO
Please use the following to answer the next question:
Louis, a long-time customer of Bedrock Insurance, was involved in a minor car accident a few months ago. Although no one was hurt, Louis has been plagued by texts and calls from a company called Accidentable offering to help him recover compensation for personal injury. Louis has heard about insurance companies selling customers' data to third parties, and he's convinced that Accidentable must have gotten his information from Bedrock Insurance.
Louis has also been receiving an increased amount of marketing information from Bedrock, trying to sell him their full range of their insurance policies.
Perturbed by this, Louis has started looking at price comparison sites on the internet and has been shocked to find that other insurers offer much cheaper rates than Bedrock, even though he has been a loyal customer for many years. When his Bedrock policy comes up for renewal, he decides to switch to Zantrum Insurance.
In order to activate his new insurance policy, Louis needs to supply Zantrum with information about his No Claims bonus, his vehicle and his driving history. After researching his rights under the GDPR, he writes to ask Bedrock to transfer his information directly to Zantrum. He also takes this opportunity to ask Bedrock to stop using his personal data for marketing purposes.
Bedrock supplies Louis with a PDF and XML (Extensible Markup Language) versions of his No Claims Certificate, but tells Louis it cannot transfer his data directly to Zantrum as this is not technically feasible. Bedrock also explains that Louis's contract included a provision whereby Louis agreed that his data could be used for marketing purposes; according to Bedrock, it is too late for Louis to change his mind about this. It angers Louis when he recalls the wording of the contract, which was filled with legal jargon and very confusing.
In the meantime, Louis is still receiving unwanted calls from Accidentable Insurance. He writes to Accidentable to ask for the name of the organization that supplied his details to them. He warns Accidentable that he plans to complain to the data protection authority, because he thinks their company has been using his data unlawfully. His letter states that he does not want his data being used by them in any way.
Accidentable's response letter confirms Louis's suspicions. Accidentable is Bedrock Insurance's wholly owned subsidiary, and they received information about Louis's accident from Bedrock shortly after Louis submitted his accident claim. Accidentable assures Louis that there has been no breach of the GDPR, as Louis's contract included, a provision in which he agreed to share his information with Bedrock's affiliates for business purposes.
Louis is disgusted by the way in which he has been treated by Bedrock, and writes to them insisting that all his information be erased from their computer system.
After Louis has exercised his right to restrict the use of his data, under what conditions would Accidentable have grounds for refusing to comply?
- A. If the accuracy of the data is not an aspect that Louis is disputing.
- B. If the data becomes necessary to defend Accidentable's legal rights.
- C. If Accidentable is entitled to use of the data as an affiliate of Bedrock.
- D. If Accidentable also uses the data to conduct public health research.
Answer: C
NEW QUESTION 95
Which of the following would most likely NOT be covered by the definition of "personal data" under the GDPR?
- A. The U.S. social security number of an American citizen living in France
- B. The unlinked aggregated data used for statistical purposes by an Italian company
- C. The payment card number of a Dutch citizen
- D. The identification number of a German candidate for a professional examination in Germany
Answer: B
NEW QUESTION 96
SCENARIO
Please use the following to answer the next question:
You have just been hired by a toy manufacturer based in Hong Kong. The company sells a broad range of dolls, action figures and plush toys that can be found internationally in a wide variety of retail stores. Although the manufacturer has no offices outside Hong Kong and in fact does not employ any staff outside Hong Kong, it has entered into a number of local distribution contracts. The toys produced by the company can be found in all popular toy stores throughout Europe, the United States and Asia. A large portion of the company's revenue is due to international sales.
The company now wishes to launch a new range of connected toys, ones that can talk and interact with children. The CEO of the company is touting these toys as the next big thing, due to the increased possibilities offered: The figures can answer children's questions on various subjects, such as mathematical calculations or the weather. Each figure is equipped with a microphone and speaker and can connect to any smartphone or tablet via Bluetooth. Any mobile device within a 10-meter radius can connect to the toys via Bluetooth as well. The figures can also be associated with other figures (from the same manufacturer) and interact with each other for an enhanced play experience.
When a child asks the toy a question, the request is sent to the cloud for analysis, and the answer is generated on cloud servers and sent back to the figure. The answer is given through the figure's integrated speakers, making it appear as though that the toy is actually responding to the child's question. The packaging of the toy does not provide technical details on how this works, nor does it mention that this feature requires an internet connection. The necessary data processing for this has been outsourced to a data center located in South Africa. However, your company has not yet revised its consumer-facing privacy policy to indicate this.
In parallel, the company is planning to introduce a new range of game systems through which consumers can play the characters they acquire in the course of playing the game. The system will come bundled with a portal that includes a Near-Field Communications (NFC) reader. This device will read an RFID tag in the action figure, making the figure come to life onscreen. Each character has its own stock features and abilities, but it is also possible to earn additional ones by accomplishing game goals. The only information stored in the tag relates to the figures' abilities. It is easy to switch characters during the game, and it is possible to bring the figure to locations outside of the home and have the character's abilities remain intact.
To ensure GDPR compliance, what should be the company's position on the issue of consent?
- A. Consent for data collection is implied through the parent's purchase of the action figure for the child.
- B. Written authorization attesting to the responsible use of children's data would need to be obtained from the supervisory authority.
- C. Parental consent for a child's use of the action figures would have to be obtained before any data could be collected.
- D. The child, as the user of the action figure, can provide consent himself, as long as no information is shared for marketing purposes.
Answer: C
NEW QUESTION 97
Which of the following was the first to implement national law for data protection in 1973?
- A. United Kingdom
- B. Sweden
- C. Germany
- D. France
Answer: B
NEW QUESTION 98
With respect to international transfers of personal data, the European Data Protection Board (EDPB) confirmed that derogations may be relied upon under what condition?
- A. Only if the Data Protection Impact Assessment (DPIA) shows low risk.
- B. If the data controller has received preapproval from a Data Protection Authority (DPA), after submitting the appropriate documents.
- C. Only as a last resort and when interpreted restrictively.
- D. When it has been determined that adequate protection can be performed.
Answer: D
NEW QUESTION 99
SCENARIO
Please use the following to answer the next question:
Ben is a member of the fitness club STAYFIT. This company has branches in many EU member states, but for the purposes of the GDPR maintains its primary establishment in France. Ben lives in Newry, Northern Ireland (part of the U.K.), and commutes across the border to work in Dundalk, Ireland. Two years ago while on a business trip, Ben was photographed while working out at a branch of STAYFIT in Frankfurt, Germany. At the time, Ben gave his consent to being included in the photograph, since he was told that it would be used for promotional purposes only. Since then, the photograph has been used in the club's U.K. brochures, and it features in the landing page of its U.K. website. However, the fitness club has recently fallen into disrepute due to widespread mistreatment of members at various branches of the club in several EU member states. As a result, Ben no longer feels comfortable with his photograph being publicly associated with the fitness club.
After numerous failed attempts to book an appointment with the manager of the local branch to discuss this matter, Ben sends a letter to STAYFIT requesting that his image be removed from the website and all promotional materials. Months pass and Ben, having received no acknowledgment of his request, becomes very anxious about this matter. After repeatedly failing to contact STAYFIT through alternate channels, he decides to take action against the company.
Ben contacts the U.K. Information Commissioner's Office ('ICO' - the U.K.'s supervisory authority) to lodge a complaint about this matter.
Assuming that multiple STAYFIT branches across several EU countries are acting as separate data controllers, and that each of those branches were responsible for mishandling Ben's request, how may Ben proceed in order to seek compensation?
- A. He will be able to sue any one of the relevant STAYFIT branches, as each one may be held liable for the entire damage.
- B. He will have to sue each STAYFIT branch so that each branch provides proportionate compensation commensurate with its contribution to the damage or distress suffered by Ben.
- C. He will be able to apply to the European Data Protection Board in order to determine which particular STAYFIT branch is liable for damages, based on the decision that was made by the board.
- D. He will have to sue the STAYFIT's head office in France, where STAYFIT has its main establishment.
Answer: D
NEW QUESTION 100
......
You can read the IAPP CIPP/E Exam certified salary below
The Average Salary of an IAPP CIPP/E Exam in
- United State - 122,750 USD
- India - 9206648 INR
- Europe - 104162 EURO
- England - 94029 POUND
CIPP-E Exam Dumps - PDF Questions and Testing Engine: https://www.lead1pass.com/IAPP/CIPP-E-practice-exam-dumps.html
Real CIPP-E Exam Dumps Questions Valid CIPP-E Dumps PDF: https://drive.google.com/open?id=1X88JL-6y7th0M8DhqOhozFO-sUgEY8v7